Find notable cyber news and cases, enriched with sources, timelines, and signals.

ClickFix Go-based macOS infostealer and crypto drainer

Malware Activity
First reported
Last updated
Happening score
H score 29
1 unique sources, 1 articles

Summary

Hide ▲

A Go-based malware delivered through ClickFix now targets macOS users and steals cryptocurrency assets plus saved credentials, creating immediate wallet-drain and account-takeover risk. It can also redirect transactions before they are signed, including partial theft rather than only full-wallet emptying. The delivery chain uses a Bash loader and Mach-O payload to stage the malware and evade macOS security prompts.

Related Happenings

ClickFix macOS Terminal-command lure campaign

Campaign
H score42 First: 07.08.2026 01:37 Last: 07.08.2026 01:37 Sources 1

How related: The targeted user received an email with a link to a page instructing them to run a command in Terminal.

About this happening: The ClickFix campaign is pushing macOS users to run a Terminal command, creating a live path to credential theft and crypto diversion. The lure arrives through email...

PylangGhost and GolangGhost ClickFix RAT delivery on Windows and macOS

Malware Activity
H score29 First: 21.07.2026 12:30 Last: 21.07.2026 12:30 Sources 1

About this happening: The PylangGhost and GolangGhost malware operation now uses ClickFix interview portals to install remote access trojans on Windows and macOS, putting Web3 a...

ClickFix-based TELEPUZ distribution campaign

Campaign
H score35 First: 16.07.2026 15:50 Last: 16.07.2026 15:50 Sources 1

About this happening: The ClickFix-based TELEPUZ distribution campaign is pushing TELEPUZ through websites infected with lures, increasing the chance that victims run malicious commands and...

ClickLock ClickFix macOS targeting campaign

Campaign
H score33 First: 16.07.2026 15:33 Last: 16.07.2026 15:33 Sources 1

About this happening: Group-IB reported a ClickLock macOS campaign that uses ClickFix paste-a-command lures and coercive app-killing loops to force victims to enter their system login...

ClickLock Stealer macOS forced-interaction infostealer activity

Malware Activity
H score27 First: 16.07.2026 15:33 Last: 16.07.2026 15:33 Sources 1

About this happening: ClickLock Stealer is a macOS information-stealing malware that uses a ClickFix-style paste into Terminal and a fake system dialog to coerce users into entering the...

Timeline

  1. 07.08.2026 01:37 2 articles · 1h ago

    Go-based ClickFix malware steals macOS credentials and crypto assets

    Initial Disclosure

    A Go-based malware delivered via ClickFix against macOS users steals cryptocurrency assets, browser-stored passwords, Apple Keychain data, and cached credentials, and it can intercept and redirect cryptocurrency transactions before they are signed, including partial theft. The payload chain uses an email link to a Terminal command, drops a Bash profiler and loader, retrieves a matching Mach-O payload, copies itself as com.apple.verified, and removes com.apple.quarantine to avoid Gatekeeper warnings.

    Show sources