BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

New Go-Based macOS Malware Drains Crypto Wallets via ClickFix

ClickFix attacks deliver Go-based macOS malware stealing cryptocurrency wallet funds, browser passwords, and iCloud Keychain.

  • ClickFix-style attacks are delivering Go-based malware on macOS that steals cryptocurrency wallet funds, browser passwords, and iCloud Keychain data.
  • The malware includes a “DRAIN” routine that siphons a portion or all of a wallet’s value, targeting Bitcoin, Ethereum, Litecoin, Dogecoin, Monero, and XRP.
  • The infection chain uses a fake system error prompt to trick victims into entering their credentials for privilege escalation.
  • Multiple recent ClickFix campaigns also leverage WebAssembly, steganography, and abused Windows binaries to distribute stealers like Lumma and Remus.

On August 7, 2026, researchers at Huntress disclosed a macOS attack chain that uses ClickFix lures to deliver a Go-based stealer capable of draining cryptocurrency wallets. The attack begins when a victim pastes a crafted command into Terminal, triggering a Bash loader that profiles the system and fetches a Mach-O payload matching the computer’s processor architecture.

- Advertisement -

The malware can capture browser-stored passwords, Apple Keychain data, and cached credentials, then sends them to a remote server operated by the threat actor. “While the malware payload is capable of stealing passwords, its most interesting function is its capability to slowly deplete cryptocurrency accounts, siphoning their contents into accounts under the threat actor’s control,” Huntress researcher Andrew Brandt said.

According to the Huntress report, the malware contains separate DRAIN routines for Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and Ripple’s XRP. These functions calculate 1% of a wallet’s value and redirect funds to attacker-controlled wallets. “It’s the first time we have seen malware capable of emptying a cryptocurrency wallet that could be used to remove any less than the entire wallet’s value,” the firm noted.

The infrastructure hosting the malicious payloads and command-and-control servers traces back to a Russian bulletproof hosting provider sanctioned by the U.S., U.K., and Australia, as reported by The Hacker News. Meanwhile, several other ClickFix campaigns have surfaced in recent weeks.

Microsoft detailed a macOS ClickFix campaign distributing MacSync and Atomic Stealer, which uses look-alike domains and server-side browser fingerprinting to conditionally serve lures. Palo Alto Networks Unit 42 described a variant that abuses the Program Compatibility Assistant to bypass heuristics, mounting a WebDAV share to load a malicious DLL via rundll32.exe.

- Advertisement -

Another ClickFix campaign employs on-the-fly WebAssembly instantiation and steganography through SVG images, using compromised websites to construct the fake verification page. Separate stealer campaigns deliver Lumma Stealer disguised as pirated movie releases of The Odyssey, and a 64-bit variant called Remus via cracked software lures hosted on SEO-poisoned fake websites.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Leopold Aschenbrenner Suspected Behind $96M AI Stock Options Bet

AI hedge fund manager Leopold Aschenbrenner is suspected of purchasing $96 million in...

Binance Launches 24/7 FX Perpetuals with USDBRL

Binance launches USDBRL perpetual futures contract on Sept. 21, offering 24/7 trading and up...

WordPress Urges Update as Click2Shell Let Admins Install Themes

WordPress patched the “Click2Shell” vulnerability in version 7.1.1, released September 17, 2026.The flaw lets...

XRP Jumps 7% as Golden Cross Looms Mid-October

XRP surged 6.93% on Friday, climbing from $1.2964 to $1.4028 before settling near $1.3863...

Bitcoin Reclaims $80K as Crypto Stocks Rally on CFTC News

Bitcoin reclaimed $80,000 on Friday for the first time in over a week, sparking...

Must Read

TOP 12 Day Trading Crypto Books For Beginners

Day trading cryptocurrencies has become an increasingly popular financial activity, offering the potential for huge returns to those who understand the market's complexities and...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading