ClickFix Attacks Drain Cryptocurrency Wallets via Go-Based macOS Malware
Cyber threat actors are leveraging ClickFix attacks to deliver a Go-based macOS malware that can drain cryptocurrency wallets, as well as steal browser-stored passwords and Apple iCloud Keychain data.
The infection chain begins with a user pasting a ClickFix command into the Terminal app, triggering the execution of a Bash profiler/loader that collects system details and retrieves a Mach-O payload compatible with the victim's processor architecture.
The malware payload is designed to check if a cryptocurrency wallet holds funds and redirect a chunk or all of it to an attacker-controlled wallet. This includes Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and Ripple's XRP.
The malicious payloads are linked back to infrastructure belonging to Aeza Group, a Russian bulletproof hosting provider sanctioned by the U.S., the U.K., and Australia for facilitating bad actors.