A Go-based malware delivered through ClickFix attacks is targeting macOS users to steal cryptocurrency assets, browser-stored passwords, Apple Keychain data, and cached credentials. It can also intercept and redirect crypto transactions, while Huntress traced the operation to infrastructure linked with Aeza Group in AS 210644. #ClickFix #macOS #Huntress #AezaGroup #AppleKeychain #Bitcoin #Litecoin #Dogecoin #Monero #Ethereum #XRP
Keypoints
- The malware is delivered through ClickFix attacks against macOS users.
- It steals browser passwords, Apple Keychain data, and cached credentials.
- It can intercept and redirect cryptocurrency transactions before they are signed.
- The payload can drain only part of a wallet and is configurable by percentage.
- Huntress linked the activity to infrastructure in AS 210644 operated by Aeza Group.