ClickFix macOS Terminal-command lure campaign
Campaign
Summary
Hide ▲
Show ▼
The ClickFix campaign is pushing macOS users to run a Terminal command, creating a live path to credential theft and crypto diversion. The lure arrives through email-delivered links that open a page with instructions to execute the command. The resulting chain loads a Bash profiler/loader and a Mach-O payload tailored to the victim system. The same activity is tied to theft of browser passwords, Apple Keychain data, cached credentials, and cryptocurrency transactions.
Related Happenings
ClickFix Go-based macOS infostealer and crypto drainer
Malware Activity
H score29
First: 07.08.2026 01:37
Last: 07.08.2026 01:37
Sources 1
How related:
A Go-based malware delivered in ClickFix attacks targeting macOS users is stealing cryptocurrency assets, browser-stored passwords, Apple Keychain data, and cached credentials.
About this happening:
A Go-based malware delivered through ClickFix now targets macOS users and steals cryptocurrency assets plus saved credentials, creating immediate wallet-drain and...
ClickFix Go-based macOS infostealer and crypto drainer
Malware ActivityHow related: A Go-based malware delivered in ClickFix attacks targeting macOS users is stealing cryptocurrency assets, browser-stored passwords, Apple Keychain data, and cached credentials.
About this happening: A Go-based malware delivered through ClickFix now targets macOS users and steals cryptocurrency assets plus saved credentials, creating immediate wallet-drain and...
Fake Bank of America phishing remote-control campaign
Campaign
H score32
First: 05.08.2026 11:00
Last: 05.08.2026 11:00
Sources 1
About this happening:
The fake Bank of America phishing campaign is delivering a multi-stage download chain that can install ScreenConnect and give attackers remote control of victim sy...
Fake Bank of America phishing remote-control campaign
CampaignAbout this happening: The fake Bank of America phishing campaign is delivering a multi-stage download chain that can install ScreenConnect and give attackers remote control of victim sy...
DOUBLECUP ClickFix-delivered CountLoader and DeviceManager malware activity
Malware Activity
H score22
First: 03.08.2026 23:01
Last: 03.08.2026 23:01
Sources 1
About this happening:
DOUBLECUP is a Russian loader-as-a-service active since early June 2026 that uses ClickFix lures and browser-cached steganographic PNGs to deliver CountLoade...
DOUBLECUP ClickFix-delivered CountLoader and DeviceManager malware activity
Malware ActivityAbout this happening: DOUBLECUP is a Russian loader-as-a-service active since early June 2026 that uses ClickFix lures and browser-cached steganographic PNGs to deliver CountLoade...
PylangGhost and GolangGhost ClickFix RAT delivery on Windows and macOS
Malware Activity
H score29
First: 21.07.2026 12:30
Last: 21.07.2026 12:30
Sources 1
About this happening:
The PylangGhost and GolangGhost malware operation now uses ClickFix interview portals to install remote access trojans on Windows and macOS, putting Web3 a...
PylangGhost and GolangGhost ClickFix RAT delivery on Windows and macOS
Malware ActivityAbout this happening: The PylangGhost and GolangGhost malware operation now uses ClickFix interview portals to install remote access trojans on Windows and macOS, putting Web3 a...
Famous Chollima ClickFake Interview recruitment scam campaign
Campaign
H score34
First: 21.07.2026 12:30
Last: 21.07.2026 12:30
Sources 1
About this happening:
A Famous Chollima recruitment scam is targeting Web3 and cryptocurrency professionals with fake job interviews and malicious assessment portals that deliver remote a...
Famous Chollima ClickFake Interview recruitment scam campaign
CampaignAbout this happening: A Famous Chollima recruitment scam is targeting Web3 and cryptocurrency professionals with fake job interviews and malicious assessment portals that deliver remote a...
Timeline
-
07.08.2026 01:37 2 articles · 18h ago
ClickFix delivers a macOS infostealer that steals Apple Keychain data and crypto assets
Technical Analysis UpdateA Go-based malware delivered through ClickFix lures against macOS users uses an email link to a page that instructs the victim to run a command in Terminal, then drops a Bash profiler and loader plus a matching Mach-O payload. The malware steals browser-stored passwords, Apple Keychain data, cached credentials, and cryptocurrency assets, can alter transactions before signing to divert funds, and uses com.apple.verified together with a removed com.apple.quarantine attribute to evade Gatekeeper. It also communicates with shared IP addresses in AS 210644 linked to the Aeza Group.
Show sources
- ClickFix attack pushes macOS infostealer for crypto theft attacks — www.bleepingcomputer.com — 07.08.2026 01:37
- ClickFix attack pushes macOS infostealer for crypto theft attacks — www.bleepingcomputer.com — 07.08.2026 01:37