bleeping-computer · Crawled Aug 7, 2026
ClickFix attack pushes macOS infostealer for crypto theft attacks
2 IoCs
Read original article ↗
AI Summary
A macOS-targeted Go-based infostealer malware distributed via ClickFix phishing attacks is stealing cryptocurrency, browser passwords, Apple Keychain data, and cached credentials. The malware establishes persistence by prompting for admin privileges using a fake error dialog and modifies cryptocurrency transactions to redirect a portion of funds to attacker-controlled wallets. It avoids Gatekeeper detection by removing the quarantine attribute and hides in a directory mimicking a legitimate macOS process. The malware communicates with C2 infrastructure hosted in AS210644, linked to the Russian Aeza Group, which has been sanctioned for providing bulletproof hosting to ransomware actors.
AI-extracted · verify before operational use