ClickFix Campaign Steals Credentials and Depletes Cryptocurrency Wallets
A Go-based macOS stealer has been discovered targeting cryptocurrency users through a ClickFix social engineering campaign. The malware steals sensitive credentials from Apple Keychain and browser stores, allowing it to gradually drain cryptocurrency balances from victim wallets.
The infection chain begins with a shell script profiler that delivers architecture-specific Mach-O payloads. Huntress analysts uncovered the threat during a retrospective hunt and identified components of a macOS-specific stealer that had remained active for roughly three months.
The investigation linked the supporting infrastructure to the Aeza Group, a sanctioned Russian bulletproof hosting provider. To mitigate this threat, users should avoid interacting with suspicious CAPTCHA prompts or following unusual instructions that require commands to be entered into Terminal.