ClickFix Go-based macOS infostealer and crypto drainer
Malware Activity
Summary
Hide ▲
Show ▼
A Go-based malware delivered through ClickFix is targeting macOS users to steal cryptocurrency assets, browser-stored passwords, Apple iCloud Keychain data, and cached credentials. The Bash profiler/loader fetches a Mach-O payload matched to the victim's CPU architecture, and the chain uses a fake prompt to obtain credentials and evade macOS defenses. The malware also includes a DRAIN routine that can siphon funds from wallets, including partial theft rather than only emptying an entire wallet. Researchers linked the payload and C2 infrastructure to Aeza Group, a sanctioned Russian bulletproof hosting provider.
Related Happenings
MacSync Stealer rotating-domain exfiltration activity
Malware Activity
H score30
First: 19.08.2026 09:01
Last: 19.08.2026 09:01
Sources 1
About this happening:
The MacSync Stealer operation has been tied to 30+ rotating domains and confirmed active data exfiltration, increasing the risk of credential theft on macOS endpoi...
MacSync Stealer rotating-domain exfiltration activity
Malware ActivityAbout this happening: The MacSync Stealer operation has been tied to 30+ rotating domains and confirmed active data exfiltration, increasing the risk of credential theft on macOS endpoi...
AmnesiaStealer macOS infostealer distributed via ClickFix
Malware Activity
H score16
First: 14.08.2026 13:45
Last: 14.08.2026 13:45
Sources 1
About this happening:
AmnesiaStealer is a Rust-based macOS infostealer spread through a counterfeit GitHub "Download for macOS" page and ClickFix-style lure. It steals Keychain, b...
AmnesiaStealer macOS infostealer distributed via ClickFix
Malware ActivityAbout this happening: AmnesiaStealer is a Rust-based macOS infostealer spread through a counterfeit GitHub "Download for macOS" page and ClickFix-style lure. It steals Keychain, b...
Go-based macOS stealer with DRAIN wallet-draining routine
Malware Activity
H score29
First: 07.08.2026 21:29
Last: 07.08.2026 21:29
Sources 1
How related:
What's notable about the malware is that it also packs in a "DRAIN" routine that checks if a cryptocurrency wallet holds funds, and if so, redirects a chunk or all of it to an attacker-controlled wallet.
About this happening:
A Go-based macOS stealer delivered through ClickFix-style attacks is stealing browser passwords, Apple iCloud Keychain data, and cached credentials while also...
Go-based macOS stealer with DRAIN wallet-draining routine
Malware ActivityHow related: What's notable about the malware is that it also packs in a "DRAIN" routine that checks if a cryptocurrency wallet holds funds, and if so, redirects a chunk or all of it to an attacker-controlled wallet.
About this happening: A Go-based macOS stealer delivered through ClickFix-style attacks is stealing browser passwords, Apple iCloud Keychain data, and cached credentials while also...
ClickFix macOS Terminal-command lure campaign
Campaign
H score42
First: 07.08.2026 01:37
Last: 07.08.2026 01:37
Sources 1
How related:
The targeted user received an email with a link to a page instructing them to run a command in Terminal.
About this happening:
The ClickFix campaign is delivering a Go-based macOS stealer through Terminal commands pasted from lure pages, creating a path to browser password theft, Apple K...
ClickFix macOS Terminal-command lure campaign
CampaignHow related: The targeted user received an email with a link to a page instructing them to run a command in Terminal.
About this happening: The ClickFix campaign is delivering a Go-based macOS stealer through Terminal commands pasted from lure pages, creating a path to browser password theft, Apple K...
DOUBLECUP ClickFix-delivered CountLoader and DeviceManager malware activity
Malware Activity
H score22
First: 03.08.2026 23:01
Last: 03.08.2026 23:01
Sources 1
About this happening:
DOUBLECUP is a Russian loader-as-a-service active since early June 2026 that uses ClickFix lures and browser-cached steganographic PNGs to deliver CountLoade...
DOUBLECUP ClickFix-delivered CountLoader and DeviceManager malware activity
Malware ActivityAbout this happening: DOUBLECUP is a Russian loader-as-a-service active since early June 2026 that uses ClickFix lures and browser-cached steganographic PNGs to deliver CountLoade...
Timeline
-
07.08.2026 01:37 3 articles · 13d ago
Go-based ClickFix malware steals macOS credentials and crypto assets
Initial DisclosureA Go-based malware delivered via ClickFix against macOS users steals cryptocurrency assets, browser-stored passwords, Apple Keychain data, and cached credentials, and it can intercept and redirect cryptocurrency transactions before they are signed, including partial theft. The payload chain uses an email link to a Terminal command, drops a Bash profiler and loader, retrieves a matching Mach-O payload, copies itself as com.apple.verified, and removes com.apple.quarantine to avoid Gatekeeper warnings.
Show sources
- ClickFix attack pushes macOS infostealer for crypto theft attacks — www.bleepingcomputer.com — 07.08.2026 01:37
- ClickFix attack pushes macOS infostealer for crypto theft attacks — www.bleepingcomputer.com — 07.08.2026 01:37
- ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets — thehackernews.com — 07.08.2026 21:29