macOS Crypto-Stealing Malware Slips Through ClickFix Attack Campaign

A dangerous new malware campaign is targeting macOS users through a technique known as ClickFix, where victims receive emails with links to pages instructing them to run commands in Terminal. Security researchers at Huntress discovered that the attack downloads a Bash script that profiles the system and retrieves a malicious payload disguised as a legitimate Apple process. By removing standard security attributes, the malware bypasses macOS Gatekeeper protections and executes without triggering security alerts.

Once installed, the Go-based infostealer aggressively harvests sensitive data including browser password databases, Apple Keychain contents, and cached credentials stored in cookies. It establishes persistence by displaying fake error prompts that trick users into entering their administrator passwords. The malware then scans storage for credential files based on specific names and extensions, giving attackers broad access to a victim's digital life.

What makes this threat particularly notable is its cryptocurrency theft capability, which goes beyond simply emptying wallets. The malware can modify transactions before they are signed and is configurable to divert only a percentage of funds, making the theft harder to detect. Huntress researchers note this is the first crypto drainer they have analyzed that deliberately steals less than the total amount, calculating exact percentages to siphon off funds quietly over time.

Read More at the original source →