hacker-news · Crawled Aug 7, 2026
ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets
Read original article ↗AI Summary
ClickFix-style attacks are delivering a Go-based macOS stealer that profiles the system, escalates privileges via a fake system error prompt, and steals sensitive data including browser passwords, Apple iCloud Keychain, and cryptocurrency wallet contents. The malware includes a 'DRAIN' routine that siphons partial or full balances from wallets supporting Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and XRP into attacker-controlled accounts. The infrastructure used in the attack is linked to Aeza Group, a Russian bulletproof hosting provider under international sanctions.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.