Skip to content
Back to Guavy Wire
Crypto

Fake CAPTCHA Checks Infect Macs with Backdoor and Crypto Mining Malware

Instruments
XMR APT
Share

A new malware campaign has been discovered targeting Mac users, using fake CAPTCHA checks to install a backdoor that steals passwords and mines cryptocurrency.

The campaign, known as ClickFix, presents itself as a legitimate human verification page from TrustKey, but in reality, it's designed to trick victims into running a malicious command in Terminal.

This allows the attackers to deploy a persistent agent on the victim's Mac, which can collect browser and wallet data, steal login passwords, and even deploy XMRig to consume the device's processing power.

The malware uses a technique called EtherHiding to evade detection, making it difficult for defenders to block or track. It also presents a counterfeit macOS System Preferences prompt to obtain the victim's login password in cleartext.

More on Crypto

Disclaimer: Guavy is a data and market intelligence provider, not an investment adviser. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc