Find notable cyber news and cases, enriched with sources, timelines, and signals.

ClickFix Go-based macOS infostealer and crypto drainer

Malware Activity
First reported
Last updated
Happening score
H score 29
2 unique sources, 2 articles

Summary

Hide ▲

A Go-based malware delivered through ClickFix is targeting macOS users to steal cryptocurrency assets, browser-stored passwords, Apple iCloud Keychain data, and cached credentials. The Bash profiler/loader fetches a Mach-O payload matched to the victim's CPU architecture, and the chain uses a fake prompt to obtain credentials and evade macOS defenses. The malware also includes a DRAIN routine that can siphon funds from wallets, including partial theft rather than only emptying an entire wallet. Researchers linked the payload and C2 infrastructure to Aeza Group, a sanctioned Russian bulletproof hosting provider.

Related Happenings

MacSync Stealer rotating-domain exfiltration activity

Malware Activity
H score30 First: 19.08.2026 09:01 Last: 19.08.2026 09:01 Sources 1

About this happening: The MacSync Stealer operation has been tied to 30+ rotating domains and confirmed active data exfiltration, increasing the risk of credential theft on macOS endpoi...

AmnesiaStealer macOS infostealer distributed via ClickFix

Malware Activity
H score16 First: 14.08.2026 13:45 Last: 14.08.2026 13:45 Sources 1

About this happening: AmnesiaStealer is a Rust-based macOS infostealer spread through a counterfeit GitHub "Download for macOS" page and ClickFix-style lure. It steals Keychain, b...

Go-based macOS stealer with DRAIN wallet-draining routine

Malware Activity
H score29 First: 07.08.2026 21:29 Last: 07.08.2026 21:29 Sources 1

How related: What's notable about the malware is that it also packs in a "DRAIN" routine that checks if a cryptocurrency wallet holds funds, and if so, redirects a chunk or all of it to an attacker-controlled wallet.

About this happening: A Go-based macOS stealer delivered through ClickFix-style attacks is stealing browser passwords, Apple iCloud Keychain data, and cached credentials while also...

ClickFix macOS Terminal-command lure campaign

Campaign
H score42 First: 07.08.2026 01:37 Last: 07.08.2026 01:37 Sources 1

How related: The targeted user received an email with a link to a page instructing them to run a command in Terminal.

About this happening: The ClickFix campaign is delivering a Go-based macOS stealer through Terminal commands pasted from lure pages, creating a path to browser password theft, Apple K...

DOUBLECUP ClickFix-delivered CountLoader and DeviceManager malware activity

Malware Activity
H score22 First: 03.08.2026 23:01 Last: 03.08.2026 23:01 Sources 1

About this happening: DOUBLECUP is a Russian loader-as-a-service active since early June 2026 that uses ClickFix lures and browser-cached steganographic PNGs to deliver CountLoade...

Timeline

  1. 07.08.2026 01:37 3 articles · 13d ago

    Go-based ClickFix malware steals macOS credentials and crypto assets

    Initial Disclosure

    A Go-based malware delivered via ClickFix against macOS users steals cryptocurrency assets, browser-stored passwords, Apple Keychain data, and cached credentials, and it can intercept and redirect cryptocurrency transactions before they are signed, including partial theft. The payload chain uses an email link to a Terminal command, drops a Bash profiler and loader, retrieves a matching Mach-O payload, copies itself as com.apple.verified, and removes com.apple.quarantine to avoid Gatekeeper warnings.

    Show sources