ClickFix Go-based macOS infostealer and crypto drainer
Malware Activity
Summary
Hide ▲
Show ▼
A Go-based malware delivered through ClickFix now targets macOS users and steals cryptocurrency assets plus saved credentials, creating immediate wallet-drain and account-takeover risk. It can also redirect transactions before they are signed, including partial theft rather than only full-wallet emptying. The delivery chain uses a Bash loader and Mach-O payload to stage the malware and evade macOS security prompts.
Related Happenings
ClickFix macOS Terminal-command lure campaign
Campaign
H score42
First: 07.08.2026 01:37
Last: 07.08.2026 01:37
Sources 1
How related:
The targeted user received an email with a link to a page instructing them to run a command in Terminal.
About this happening:
The ClickFix campaign is pushing macOS users to run a Terminal command, creating a live path to credential theft and crypto diversion. The lure arrives through email...
ClickFix macOS Terminal-command lure campaign
CampaignHow related: The targeted user received an email with a link to a page instructing them to run a command in Terminal.
About this happening: The ClickFix campaign is pushing macOS users to run a Terminal command, creating a live path to credential theft and crypto diversion. The lure arrives through email...
PylangGhost and GolangGhost ClickFix RAT delivery on Windows and macOS
Malware Activity
H score29
First: 21.07.2026 12:30
Last: 21.07.2026 12:30
Sources 1
About this happening:
The PylangGhost and GolangGhost malware operation now uses ClickFix interview portals to install remote access trojans on Windows and macOS, putting Web3 a...
PylangGhost and GolangGhost ClickFix RAT delivery on Windows and macOS
Malware ActivityAbout this happening: The PylangGhost and GolangGhost malware operation now uses ClickFix interview portals to install remote access trojans on Windows and macOS, putting Web3 a...
ClickFix-based TELEPUZ distribution campaign
Campaign
H score35
First: 16.07.2026 15:50
Last: 16.07.2026 15:50
Sources 1
About this happening:
The ClickFix-based TELEPUZ distribution campaign is pushing TELEPUZ through websites infected with lures, increasing the chance that victims run malicious commands and...
ClickFix-based TELEPUZ distribution campaign
CampaignAbout this happening: The ClickFix-based TELEPUZ distribution campaign is pushing TELEPUZ through websites infected with lures, increasing the chance that victims run malicious commands and...
ClickLock ClickFix macOS targeting campaign
Campaign
H score33
First: 16.07.2026 15:33
Last: 16.07.2026 15:33
Sources 1
About this happening:
Group-IB reported a ClickLock macOS campaign that uses ClickFix paste-a-command lures and coercive app-killing loops to force victims to enter their system login...
ClickLock ClickFix macOS targeting campaign
CampaignAbout this happening: Group-IB reported a ClickLock macOS campaign that uses ClickFix paste-a-command lures and coercive app-killing loops to force victims to enter their system login...
ClickLock Stealer macOS forced-interaction infostealer activity
Malware Activity
H score27
First: 16.07.2026 15:33
Last: 16.07.2026 15:33
Sources 1
About this happening:
ClickLock Stealer is a macOS information-stealing malware that uses a ClickFix-style paste into Terminal and a fake system dialog to coerce users into entering the...
ClickLock Stealer macOS forced-interaction infostealer activity
Malware ActivityAbout this happening: ClickLock Stealer is a macOS information-stealing malware that uses a ClickFix-style paste into Terminal and a fake system dialog to coerce users into entering the...
Timeline
-
07.08.2026 01:37 2 articles · 18h ago
Go-based ClickFix malware steals macOS credentials and crypto assets
Initial DisclosureA Go-based malware delivered via ClickFix against macOS users steals cryptocurrency assets, browser-stored passwords, Apple Keychain data, and cached credentials, and it can intercept and redirect cryptocurrency transactions before they are signed, including partial theft. The payload chain uses an email link to a Terminal command, drops a Bash profiler and loader, retrieves a matching Mach-O payload, copies itself as com.apple.verified, and removes com.apple.quarantine to avoid Gatekeeper warnings.
Show sources
- ClickFix attack pushes macOS infostealer for crypto theft attacks — www.bleepingcomputer.com — 07.08.2026 01:37
- ClickFix attack pushes macOS infostealer for crypto theft attacks — www.bleepingcomputer.com — 07.08.2026 01:37