ClickFix-style lures are being used to deliver a Go-based macOS stealer that can harvest browser passwords, Apple iCloud Keychain data, cached credentials, and cryptocurrency holdings. The campaign also uses Aeza Group infrastructure and joins a broader wave of ClickFix attacks tied to MacSync, Atomic Stealer, Lumma Stealer, and Remus. #ClickFix #AezaGroup #MacSync #AtomicStealer #LummaStealer #Remus
Keypoints
- The attack starts when victims paste a ClickFix command into Terminal.
- A Bash loader profiles the host and downloads a matching Mach-O payload.
- The Go-based stealer can steal browser passwords, Keychain data, and cached credentials.
- A DRAIN routine can divert cryptocurrency funds from wallets to attacker-controlled accounts.
- The malicious infrastructure is linked to Aeza Group, a sanctioned Russian bulletproof hoster.
Read More: https://thehackernews.com/2026/08/clickfix-attacks-deliver-macos-stealer.html