ClickFix attacks are delivering macOS malware that steals credentials and can drain cryptocurrency wallets, Huntress researchers warn.
Cybercriminals are using ClickFix-style attacks to distribute a macOS information stealer capable of harvesting credentials and potentially draining cryptocurrency wallets, according to security researchers at Huntress.
The malware was identified during a retrospective Huntress investigation in June 2026, after researchers examined an infection that had occurred roughly three months earlier. The incident involved a user who had been tricked into pasting a malicious command into the macOS Terminal.
The malware is written in Go and uses a Bash-based loader to profile the infected system before downloading a Mach-O payload suited to the device’s processor architecture. The stealer can target browser credentials and information stored in Apple’s Keychain.
The malware also attempts to obtain the victim’s system password. Huntress found that it uses an osascript dialog to display a fake prompt and persuade the victim to enter their credentials. Obtaining the password can give the malware additional privileges and allow it to make further changes to the system.
The initial ClickFix command also attempts to make the activity less visible by clearing the Terminal display and removing the command from the user’s shell history.
One of the more unusual capabilities identified by Huntress is a component referred to as “DRAIN”, which targets cryptocurrency wallets. The malware can check wallet balances and redirect part or potentially all of the available funds to an address controlled by the attacker.
Huntress identified cryptocurrency-specific routines targeting Bitcoin, Litecoin, Dogecoin, Ethereum, XRP and Monero. The researchers also found code capable of calculating the value of one percent of a wallet’s balance. A separate DRAIN_PCT variable determines how much of the balance is ultimately targeted, meaning the malware is not necessarily limited to emptying an entire wallet.
Huntress said the ability to remove only a portion of a cryptocurrency wallet’s balance was notable because it differs from malware designed simply to drain wallets completely.
The attack relies on ClickFix, a social engineering technique that presents victims with fake verification prompts, error messages or other instructions designed to persuade them to copy and execute commands themselves. Rather than automatically exploiting the computer, the attacker manipulates the victim into carrying out the initial execution.
Huntress linked infrastructure used to host the malware and operate its command-and-control systems to Aeza Group, a Russian bulletproof hosting provider. The company has been sanctioned by the United States, United Kingdom and Australia over allegations involving infrastructure provided to cybercriminal groups.
The discovery adds to growing evidence that ClickFix has become an effective delivery method for malware targeting macOS users. Other campaigns have used similar social engineering techniques to distribute information stealers and other malicious software.
The latest campaign also demonstrates why users should be cautious when websites instruct them to open Terminal and paste commands. A legitimate website or security check should not normally require users to execute unknown commands simply to verify that they are human or resolve an error.
For cryptocurrency users, the incident highlights an additional risk. A compromised Mac can expose not only passwords and stored credentials but potentially the funds held in locally accessible cryptocurrency wallets.
Source : Huntress and The Hacker News
Related articles :
__Reports are sourced from official documents, law-enforcement updates, and credible investigations.
Discover additional reports, market trends, crime analysis and Harm Reduction articles on DarkDotWeb to stay informed about the latest dark web operations.__