ClickFix Malware Targets macOS Devices, Steals Cryptocurrency Assets
ClickFix attacks have been used to deliver a Go-based malware that can steal cryptocurrency assets and browser-stored passwords from macOS devices. The malware, which is designed to drain cryptocurrency wallets, uses a shell script to profile the host and then fetches a macOS malware payload compatible with the computer's CPU architecture.
The attack chain begins with pasting a ClickFix command into the Terminal app, triggering the execution of a Bash profiler/loader that collects system details and retrieves a Mach-O payload matching the victim's processor architecture. The payload is a Go-based stealer that captures browser passwords, Apple Keychain data, and cached credentials and transmits them to a remote server operated by the threat actor.
The malware contains a 'DRAIN' routine that checks if a cryptocurrency wallet holds funds and redirects a chunk or all of it to an attacker-controlled wallet. This feature is notable as it can empty a cryptocurrency wallet without removing its entire value, and separate functions are used to determine how much 1% of the wallet's contents is worth depending on the targeted cryptocurrency.
The server staging malicious payloads and the command-and-control (C2) server all link back to infrastructure belonging to Aeza Group, a Russian bulletproof hosting provider sanctioned by the U.S., the U.K., and Australia for facilitating bad actors. The disclosure comes as several ClickFix attacks have been reported in recent weeks.