bleeping-computer · Crawled Aug 7, 2026

ClickFix attack pushes macOS infostealer for crypto theft attacks

2 IoCs
Read original article ↗

AI Summary

A macOS-targeted Go-based infostealer malware distributed via ClickFix phishing attacks is stealing cryptocurrency, browser passwords, Apple Keychain data, and cached credentials. The malware establishes persistence by prompting for admin privileges using a fake error dialog and modifies cryptocurrency transactions to redirect a portion of funds to attacker-controlled wallets. It avoids Gatekeeper detection by removing the quarantine attribute and hides in a directory mimicking a legitimate macOS process. The malware communicates with C2 infrastructure hosted in AS210644, linked to the Russian Aeza Group, which has been sanctioned for providing bulletproof hosting to ransomware actors.

AI-extracted · verify before operational use

Indicators of Compromise 2 extracted

Type Value Detail
Filename com.apple.verified Details →
Filename trustd Details →