ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets

August 7, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: thehackernews.com

Threat Risk: High
Victim: macOS users and cryptocurrency holders
Incident: A Go-based stealer is being deployed via ClickFix social engineering to steal credentials and drain crypto wallets.
Impact: Complete loss of cryptocurrency funds and compromise of system-wide saved passwords and keychain data.
Attacker: Unidentified threat actors using Aeza Group infrastructure
Analysis: The attack chain tricks users into pasting malicious commands into the macOS Terminal, leading to the deployment of a Go-based stealer. This malware targets iCloud Keychain and browser credentials while specifically targeting various cryptocurrency wallets. A notable feature is the ‘DRAIN’ routine, which can stealthily remove specific percentages of a wallet’s balance to evade immediate detection.
Recommendations: Train users to never paste unknown commands into the Terminal or system command prompts.; Implement hardware-based MFA for cryptocurrency wallets and critical system accounts.; Remain vigilant against unexpected system error prompts requesting administrative credentials.
Source: The Hacker News

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *