ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets
thehackernews.com Aug 8, 2026

ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets

AI-summarised brief · reviewed before publication

ClickFix‑style attacks now deliver a Go‑based macOS stealer that siphons cryptocurrency while exfiltrating passwords, iCloud Keychain entries and cached credentials. The chain begins when a victim pastes a ClickFix command into Terminal, launching a Bash profiler that gathers system data and pulls a Mach‑O payload matching the CPU architecture. The payload escalates privileges via a fake error prompt, then transmits stolen data to a remote server. Its distinctive “DRAIN” routine checks a wallet’s balance and redirects a configurable portion—down to 1 %—to attacker‑controlled addresses, supporting Bitcoin, Litecoin, Dogecoin, Monero, Ethereum and XRP. All infrastructure points to the Aeza Group, a Russian bullet‑proof hosting service sanctioned by the U.S., U.K. and Australia. Recent weeks have seen a surge in ClickFix incidents alongside other stealer campaigns distributing Lumma and Remus variants.

💡 Why It Matters

  • · By directly emptying crypto wallets, the malware turns credential theft into immediate financial loss, raising the stakes for macOS users and enterprise security teams.