ClickFix Delivers Go-Based macOS Infostealer
Huntress discovers macOS stealer via ClickFix, targeting crypto wallets and credentials.
Huntress, a managed detection and response (MDR) specialist, has uncovered a new strain of infostealing malware aimed at macOS users, delivered through ClickFix social engineering campaigns. The malware, which is Go-based, is designed to swipe browser password stores, Apple Keychain data, and cached credentials, and can also drain cryptocurrency wallets if it finds funds. The discovery, made in June 2026, highlights how attackers continue to adapt social engineering tactics to target Apple's ecosystem.
ClickFix Deception Explained
The attack chain begins with a popup window that mimics a CAPTCHA prompt, a technique known as ClickFix. Huntress explains in a blog post that the window instructs the target to copy a long command string and paste it into the Terminal application on their Mac. This command then downloads and executes the initial stage of the attack, a method that relies on user interaction but can be highly effective due to the perceived legitimacy of the CAPTCHA.
Bash Loader and Payload Fetch
In this particular campaign, the command fetches a Bash profiler/loader that collects system details before retrieving a Mac-native Mach-O payload tailored to the victim's processor architecture. This two-stage approach ensures the final payload is compatible with the target system, increasing the chances of successful infection.
Go-Based Stealer's Capabilities
The final payload is a Go-based stealer built to scrape browser password stores, Apple Keychain data, and cached credentials from the infected system. Huntress notes that the malware also includes a DRAIN function, which checks whether a cryptocurrency wallet holds funds and then redirects all or part of that balance to attacker-controlled wallets. This dual focus on credentials and crypto makes it a potent threat for both personal and financial data.
Infrastructure Tied to Sanctioned Host
The loader, payload hosting, and command and control (C2) all link back to Aeza Group, a sanctioned Russian bulletproof hoster known for enabling cybercrime. This connection underscores the criminal ecosystem behind the campaign, though Huntress does not specify whether the group itself is the operator or merely provides infrastructure.
Mitigation Advice from Huntress
Huntress advises organizations to mitigate ClickFix threats through user education and by installing malicious script mitigation browser add-ons like NoScript. Additionally, network devices such as Pi-Hole DNS can block known-bad domains from resolving, reducing the chance of popups appearing. These measures aim to prevent users from ever reaching the point of executing the malicious command.
If Infected: Immediate Isolation
For those who fall victim, Huntress emphasizes the importance of immediate action: “If a user inadvertently follows through with a ClickFix exploit, it is imperative that the user inform their IT team immediately and that the machine be brought into an isolation mode.” The company also reassures that the malware may or may not achieve persistence, but it is easily remediated by deleting any copies of the binary left behind on the machine, after which it will not spontaneously reconstitute itself.
Why It Matters
This discovery underscores the evolving tactics of cybercriminals targeting macOS users, a platform often perceived as more secure. The integration of crypto-draining capabilities indicates a shift toward directly monetizing infected systems, rather than just harvesting credentials. For enterprises, the ClickFix vector demonstrates that social engineering remains a primary entry point, even for technical users. The tie to a sanctioned hoster suggests that takedowns of such infrastructure could disrupt campaigns, but until then, user awareness and swift incident response are critical defenses. This could mean that macOS users, who may have let their guard down, need to treat ClickFix prompts with the same skepticism as any unsolicited command.
Sources
- Infosecurity Magazine Original source
Continue Reading
Hostile SIMs exploit spec-compliant commands
Malicious SIM cards can force phones to leak files, drop to 2G, or crash—by abusing standard SIM commands.
Gray to White: A Hacker's Redemption Arc
Marcus Hutchins, who halted WannaCry, recounts his path from malware author to security researcher.
Cyber Prep Gap Leaves UK Factories Vulnerable
New Make UK report finds half of UK manufacturers lack a formal cyber incident response plan despite rising incidents.