ClickFix Campaign Deploys macOS Stealer With Crypto-Draining Capabilities
Huntress discovered a Go-based macOS infostealer delivered through ClickFix social engineering, which tricks users into running a malicious command in Terminal. The command downloads a Bash loader that profiles the system and installs a Mach-O payload matched to the Mac’s processor architecture. The malware steals browser passwords, Apple Keychain data, and cached credentials, while its DRAIN function can transfer cryptocurrency to attacker-controlled wallets. Organizations should strengthen user awareness and DNS filtering, while affected devices should be isolated immediately and inspected for malicious binaries.
Reference: infosecurity-magazine.com