Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
macOS Malware Steals Crypto via ClickFix Attacks

macOS Malware Steals Crypto via ClickFix Attacks

Posted on August 7, 2026 By CWS

Recent ClickFix attacks have emerged as a significant threat, targeting macOS users with a sophisticated malware designed to steal cryptocurrency and sensitive credentials. This malicious campaign employs a Go-based malware that infiltrates users’ systems, taking aim at browser-stored passwords, Apple iCloud Keychain data, and cached credentials.

Infection Chain and Malware Functionality

The infection begins with a ClickFix command executed within the macOS Terminal app. This action initiates a Bash script that gathers detailed system information before downloading a Mach-O payload suited to the computer’s architecture. The payload, a Go-based stealer, effectively captures and transmits sensitive data to a remote server controlled by cybercriminals.

Security researcher Andrew Brandt from Huntress highlights the malware’s unique capability to gradually deplete cryptocurrency accounts. It achieves this by siphoning funds into wallets managed by the attackers, posing a severe risk to digital assets.

Privilege Escalation and Cryptocurrency Theft

To enhance its effectiveness, the malware seeks to escalate privileges by deceiving users into entering their system credentials through a fabricated system error prompt. Once it gains the necessary access, the malware activates its “DRAIN” routine, targeting cryptocurrency wallets.

This routine is engineered to check for available funds in wallets and redirect them to addresses controlled by the attackers. Multiple cryptocurrency versions of this function exist, affecting Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and XRP.

Infrastructure and Broader Campaigns

The infrastructure supporting these attacks is linked to Aeza Group, a Russian bulletproof hosting provider under international sanctions. This connection highlights the organized nature of the operation, involving sophisticated server staging and command-and-control mechanisms.

ClickFix attacks are not limited to macOS. Variants have exploited Windows systems using legitimate binaries to bypass security measures, and some campaigns employ advanced techniques like WebAssembly and steganography to evade detection. This broadens the scope and impact of these cyber threats.

Conclusion and Future Implications

The rise of ClickFix attacks underscores the urgent need for robust cybersecurity measures to protect digital assets. As attackers continue to refine their methods, staying informed and vigilant is essential to safeguarding personal and financial information.

Proactive measures, including regular system updates and awareness of phishing tactics, are crucial in mitigating the risks posed by these sophisticated malware campaigns. The cybersecurity community must remain alert to evolving threats that challenge both individual and organizational security.

The Hacker News Tags:Aeza Group, Apple Keychain, bulletproof hosting, ClickFix, credential theft, cryptocurrency theft, cryptocurrency wallets, cyber threat, Cybersecurity, Go-based malware, Huntress research, macOS security, malware attacks, malware payload, social engineering

Post navigation

Previous Post: Malware Exploits Windows Hello Keys to Access Entra ID
Next Post: ChainDrop Worm Targets npm Packages for Credential Theft

Related Posts

Have You Turned Off Your Virtual Oven? Have You Turned Off Your Virtual Oven? The Hacker News
SolarWinds Fixes Major Flaws in Serv-U Software SolarWinds Fixes Major Flaws in Serv-U Software The Hacker News
ClickFix Campaigns Exploit Fake AI Tools to Spread MacSync ClickFix Campaigns Exploit Fake AI Tools to Spread MacSync The Hacker News
Iranian Hackers Use Job Offers to Spread Cross-Platform Malware Iranian Hackers Use Job Offers to Spread Cross-Platform Malware The Hacker News
Cracked Software and YouTube Videos Spread CountLoader and GachiLoader Malware Cracked Software and YouTube Videos Spread CountLoader and GachiLoader Malware The Hacker News
Key SOC Steps to Minimize Incident Risks Key SOC Steps to Minimize Incident Risks The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • WordPress Patch Fixes Critical Comment2Shell Vulnerability
  • Hidden Setting in Muse AI Poses Security Threat
  • Hackers Exploit Microsoft Teams for Password Theft
  • Critical Vulnerability in Meta’s Muse AI Agent Exposed
  • US-China Talks Propose AI Alert System for Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • WordPress Patch Fixes Critical Comment2Shell Vulnerability
  • Hidden Setting in Muse AI Poses Security Threat
  • Hackers Exploit Microsoft Teams for Password Theft
  • Critical Vulnerability in Meta’s Muse AI Agent Exposed
  • US-China Talks Propose AI Alert System for Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark