Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
macOS Malware Steals Crypto via ClickFix Attacks

macOS Malware Steals Crypto via ClickFix Attacks

Posted on August 7, 2026 By CWS

Recent ClickFix attacks have emerged as a significant threat, targeting macOS users with a sophisticated malware designed to steal cryptocurrency and sensitive credentials. This malicious campaign employs a Go-based malware that infiltrates users’ systems, taking aim at browser-stored passwords, Apple iCloud Keychain data, and cached credentials.

Infection Chain and Malware Functionality

The infection begins with a ClickFix command executed within the macOS Terminal app. This action initiates a Bash script that gathers detailed system information before downloading a Mach-O payload suited to the computer’s architecture. The payload, a Go-based stealer, effectively captures and transmits sensitive data to a remote server controlled by cybercriminals.

Security researcher Andrew Brandt from Huntress highlights the malware’s unique capability to gradually deplete cryptocurrency accounts. It achieves this by siphoning funds into wallets managed by the attackers, posing a severe risk to digital assets.

Privilege Escalation and Cryptocurrency Theft

To enhance its effectiveness, the malware seeks to escalate privileges by deceiving users into entering their system credentials through a fabricated system error prompt. Once it gains the necessary access, the malware activates its “DRAIN” routine, targeting cryptocurrency wallets.

This routine is engineered to check for available funds in wallets and redirect them to addresses controlled by the attackers. Multiple cryptocurrency versions of this function exist, affecting Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and XRP.

Infrastructure and Broader Campaigns

The infrastructure supporting these attacks is linked to Aeza Group, a Russian bulletproof hosting provider under international sanctions. This connection highlights the organized nature of the operation, involving sophisticated server staging and command-and-control mechanisms.

ClickFix attacks are not limited to macOS. Variants have exploited Windows systems using legitimate binaries to bypass security measures, and some campaigns employ advanced techniques like WebAssembly and steganography to evade detection. This broadens the scope and impact of these cyber threats.

Conclusion and Future Implications

The rise of ClickFix attacks underscores the urgent need for robust cybersecurity measures to protect digital assets. As attackers continue to refine their methods, staying informed and vigilant is essential to safeguarding personal and financial information.

Proactive measures, including regular system updates and awareness of phishing tactics, are crucial in mitigating the risks posed by these sophisticated malware campaigns. The cybersecurity community must remain alert to evolving threats that challenge both individual and organizational security.

The Hacker News Tags:Aeza Group, Apple Keychain, bulletproof hosting, ClickFix, credential theft, cryptocurrency theft, cryptocurrency wallets, cyber threat, Cybersecurity, Go-based malware, Huntress research, macOS security, malware attacks, malware payload, social engineering

Post navigation

Previous Post: Malware Exploits Windows Hello Keys to Access Entra ID
Next Post: ChainDrop Worm Targets npm Packages for Credential Theft

Related Posts

Severe Figma MCP Vulnerability Lets Hackers Execute Code Remotely — Patch Now Severe Figma MCP Vulnerability Lets Hackers Execute Code Remotely — Patch Now The Hacker News
New YiBackdoor Malware Shares Major Code Overlaps with IcedID and Latrodectus New YiBackdoor Malware Shares Major Code Overlaps with IcedID and Latrodectus The Hacker News
U.S. Sanctions North Korean Andariel Hacker Behind Fraudulent IT Worker Scheme U.S. Sanctions North Korean Andariel Hacker Behind Fraudulent IT Worker Scheme The Hacker News
OpenAI Halts AI Model Astra Over Cybersecurity Concerns OpenAI Halts AI Model Astra Over Cybersecurity Concerns The Hacker News
Anthropic’s AI Models Breach Security in Tests Anthropic’s AI Models Breach Security in Tests The Hacker News
Airline Hacks, Citrix 0-Day, Outlook Malware, Banking Trojans and more Airline Hacks, Citrix 0-Day, Outlook Malware, Banking Trojans and more The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hidden Setting in Muse AI Poses Security Threat
  • Hackers Exploit Microsoft Teams for Password Theft
  • Critical Vulnerability in Meta’s Muse AI Agent Exposed
  • US-China Talks Propose AI Alert System for Security
  • North Korea’s VPN Infrastructure Exposed by TLS Certificate

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hidden Setting in Muse AI Poses Security Threat
  • Hackers Exploit Microsoft Teams for Password Theft
  • Critical Vulnerability in Meta’s Muse AI Agent Exposed
  • US-China Talks Propose AI Alert System for Security
  • North Korea’s VPN Infrastructure Exposed by TLS Certificate

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark