- ClickFix-style attacks are delivering Go-based malware on macOS that steals cryptocurrency wallet funds, browser passwords, and iCloud Keychain data.
- The malware includes a “DRAIN” routine that siphons a portion or all of a wallet’s value, targeting Bitcoin, Ethereum, Litecoin, Dogecoin, Monero, and XRP.
- The infection chain uses a fake system error prompt to trick victims into entering their credentials for privilege escalation.
- Multiple recent ClickFix campaigns also leverage WebAssembly, steganography, and abused Windows binaries to distribute stealers like Lumma and Remus.
On August 7, 2026, researchers at Huntress disclosed a macOS attack chain that uses ClickFix lures to deliver a Go-based stealer capable of draining cryptocurrency wallets. The attack begins when a victim pastes a crafted command into Terminal, triggering a Bash loader that profiles the system and fetches a Mach-O payload matching the computer’s processor architecture.
The malware can capture browser-stored passwords, Apple Keychain data, and cached credentials, then sends them to a remote server operated by the threat actor. “While the malware payload is capable of stealing passwords, its most interesting function is its capability to slowly deplete cryptocurrency accounts, siphoning their contents into accounts under the threat actor’s control,” Huntress researcher Andrew Brandt said.
According to the Huntress report, the malware contains separate DRAIN routines for Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and Ripple’s XRP. These functions calculate 1% of a wallet’s value and redirect funds to attacker-controlled wallets. “It’s the first time we have seen malware capable of emptying a cryptocurrency wallet that could be used to remove any less than the entire wallet’s value,” the firm noted.
The infrastructure hosting the malicious payloads and command-and-control servers traces back to a Russian bulletproof hosting provider sanctioned by the U.S., U.K., and Australia, as reported by The Hacker News. Meanwhile, several other ClickFix campaigns have surfaced in recent weeks.
Microsoft detailed a macOS ClickFix campaign distributing MacSync and Atomic Stealer, which uses look-alike domains and server-side browser fingerprinting to conditionally serve lures. Palo Alto Networks Unit 42 described a variant that abuses the Program Compatibility Assistant to bypass heuristics, mounting a WebDAV share to load a malicious DLL via rundll32.exe.
Another ClickFix campaign employs on-the-fly WebAssembly instantiation and steganography through SVG images, using compromised websites to construct the fake verification page. Separate stealer campaigns deliver Lumma Stealer disguised as pirated movie releases of The Odyssey, and a 64-bit variant called Remus via cracked software lures hosted on SEO-poisoned fake websites.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
