Fake error prompts on Mac lead to wallet-draining stealer

Huntress documents a macOS ClickFix stealer that can drain crypto wallets and keychains.

CSBadmin
1 Min Read

Huntress researcher Andrew Brandt documented ClickFix-style attacks delivering a Go-based stealer for macOS that drains cryptocurrency wallets and captures browser passwords, iCloud Keychain data, and cached credentials.

The infection starts when a victim pastes a ClickFix command into Terminal. A Bash profiler gathers system details, pulls a Mach-O payload built for the machine’s chip, then shows a phony unexpected system error dialog to coax out admin credentials for privilege escalation.

A built-in routine named DRAIN inspects crypto wallets and forwards some or all of their contents to an address the attackers control. Separate functions cover Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and XRP, complete with logic that calculates what one percent of a wallet’s balance is worth.

It is the first time researchers have seen malware capable of removing less than the entire value of a wallet, the firm said.

Payload staging and command-and-control infrastructure trace back to Aeza Group, a Russian bulletproof hosting provider sanctioned by the U.S., the U.K., and Australia. Mac users should avoid pasting commands from web pages and treat system password prompts outside a known update flow with suspicion.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.