Go-based macOS stealer with DRAIN wallet-draining routine
Malware Activity
Summary
Hide ▲
Show ▼
A Go-based macOS stealer delivered through ClickFix-style attacks is stealing browser passwords, Apple iCloud Keychain data, and cached credentials while also siphoning cryptocurrency from infected wallets. The malware's DRAIN routine increases financial risk for macOS users by redirecting wallet contents to attacker-controlled accounts.
Related Happenings
ClickFix macOS Terminal-command lure campaign
Campaign
H score42
First: 07.08.2026 01:37
Last: 07.08.2026 01:37
Sources 1
How related:
The attack chain begins with pasting a ClickFix command into the Terminal app, triggering the execution of a Bash profiler/loader that collects extensive system details and then retrieves a Mach-O payload that matches the victim's processor architecture.
About this happening:
The ClickFix campaign is delivering a Go-based macOS stealer through Terminal commands pasted from lure pages, creating a path to browser password theft, Apple K...
ClickFix macOS Terminal-command lure campaign
CampaignHow related: The attack chain begins with pasting a ClickFix command into the Terminal app, triggering the execution of a Bash profiler/loader that collects extensive system details and then retrieves a Mach-O payload that matches the victim's processor architecture.
About this happening: The ClickFix campaign is delivering a Go-based macOS stealer through Terminal commands pasted from lure pages, creating a path to browser password theft, Apple K...
ClickFix Go-based macOS infostealer and crypto drainer
Malware Activity
H score29
First: 07.08.2026 01:37
Last: 07.08.2026 01:37
Sources 1
How related:
ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials.
About this happening:
A Go-based malware delivered through ClickFix is targeting macOS users to steal cryptocurrency assets, browser-stored passwords, Apple iCloud Keychain data...
ClickFix Go-based macOS infostealer and crypto drainer
Malware ActivityHow related: ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials.
About this happening: A Go-based malware delivered through ClickFix is targeting macOS users to steal cryptocurrency assets, browser-stored passwords, Apple iCloud Keychain data...
PylangGhost and GolangGhost ClickFix RAT delivery on Windows and macOS
Malware Activity
H score29
First: 21.07.2026 12:30
Last: 21.07.2026 12:30
Sources 1
About this happening:
The PylangGhost and GolangGhost malware operation now uses ClickFix interview portals to install remote access trojans on Windows and macOS, putting Web3 a...
PylangGhost and GolangGhost ClickFix RAT delivery on Windows and macOS
Malware ActivityAbout this happening: The PylangGhost and GolangGhost malware operation now uses ClickFix interview portals to install remote access trojans on Windows and macOS, putting Web3 a...
ClickLock Stealer macOS forced-interaction infostealer activity
Malware Activity
H score27
First: 16.07.2026 15:33
Last: 16.07.2026 15:33
Sources 1
About this happening:
ClickLock Stealer is a macOS information-stealing malware that uses a ClickFix-style paste into Terminal and a fake system dialog to coerce users into entering the...
ClickLock Stealer macOS forced-interaction infostealer activity
Malware ActivityAbout this happening: ClickLock Stealer is a macOS information-stealing malware that uses a ClickFix-style paste into Terminal and a fake system dialog to coerce users into entering the...
CrashStealer macOS information stealer activity
Malware Activity
H score10
First: 13.07.2026 20:36
Last: 13.07.2026 20:36
Sources 1
About this happening:
CrashStealer is a macOS information-stealing malware that was tracked in May and seen in attacks in early July. It impersonates Apple's crash-reporting tool by...
CrashStealer macOS information stealer activity
Malware ActivityAbout this happening: CrashStealer is a macOS information-stealing malware that was tracked in May and seen in attacks in early July. It impersonates Apple's crash-reporting tool by...
Timeline
-
07.08.2026 21:29 2 articles · 3h ago
ClickFix-style attacks deliver a Go-based macOS stealer that drains crypto wallets
Initial DisclosureClickFix-style attacks deliver a Go-based macOS stealer to macOS users through a pasted command in the Terminal app that launches a Bash profiler/loader, fetches a Mach-O payload matched to the victim's CPU architecture, steals browser passwords, Apple Keychain data, and cached credentials, and includes a DRAIN routine that can redirect cryptocurrency funds to an attacker-controlled wallet. The malicious payload staging and command-and-control infrastructure link back to Aeza Group, a Russian bulletproof hosting provider sanctioned by the U.S., the U.K., and Australia.
Show sources
- ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets — thehackernews.com — 07.08.2026 21:29
- ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets — thehackernews.com — 07.08.2026 21:29