Fake CAPTCHA Checks Infect Macs with Backdoor and Crypto Mining Malware
A new malware campaign has been discovered targeting Mac users, using fake CAPTCHA checks to install a backdoor that steals passwords and mines cryptocurrency.
The campaign, known as ClickFix, presents itself as a legitimate human verification page from TrustKey, but in reality, it's designed to trick victims into running a malicious command in Terminal.
This allows the attackers to deploy a persistent agent on the victim's Mac, which can collect browser and wallet data, steal login passwords, and even deploy XMRig to consume the device's processing power.
The malware uses a technique called EtherHiding to evade detection, making it difficult for defenders to block or track. It also presents a counterfeit macOS System Preferences prompt to obtain the victim's login password in cleartext.