ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets

ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets
ClickFix-style lures are being used to deliver a Go-based macOS stealer that can harvest browser passwords, Apple iCloud Keychain data, cached credentials, and cryptocurrency holdings. The campaign also uses Aeza Group infrastructure and joins a broader wave of ClickFix attacks tied to MacSync, Atomic Stealer, Lumma Stealer, and Remus. #ClickFix #AezaGroup #MacSync #AtomicStealer #LummaStealer #Remus

Keypoints

  • The attack starts when victims paste a ClickFix command into Terminal.
  • A Bash loader profiles the host and downloads a matching Mach-O payload.
  • The Go-based stealer can steal browser passwords, Keychain data, and cached credentials.
  • A DRAIN routine can divert cryptocurrency funds from wallets to attacker-controlled accounts.
  • The malicious infrastructure is linked to Aeza Group, a sanctioned Russian bulletproof hoster.

Read More: https://thehackernews.com/2026/08/clickfix-attacks-deliver-macos-stealer.html