Find notable cyber news and cases, enriched with sources, timelines, and signals.

ClickFix macOS Terminal-command lure campaign

Campaign
First reported
Last updated
Happening score
H score 42
3 unique sources, 3 articles

Summary

Hide ▲

The ClickFix campaign is delivering a Go-based macOS stealer through Terminal commands pasted from lure pages, creating a path to browser password theft, Apple Keychain theft, cached-credential theft, and cryptocurrency diversion. The infection chain drops a Bash profiler/loader and then a Mach-O payload matched to the victim's CPU architecture. The malware uses a fake system prompt, com.apple.verified, and a removed com.apple.quarantine attribute to reduce warnings and prompt credential entry. Infrastructure tied to the activity includes AS 210644 and Aeza Group.

Related Happenings

MacSync Stealer rotating-domain exfiltration activity

Malware Activity
H score30 First: 19.08.2026 09:01 Last: 19.08.2026 09:01 Sources 1

About this happening: The MacSync Stealer operation has been tied to 30+ rotating domains and confirmed active data exfiltration, increasing the risk of credential theft on macOS endpoi...

AmnesiaStealer macOS infostealer distributed via ClickFix

Malware Activity
H score16 First: 14.08.2026 13:45 Last: 14.08.2026 13:45 Sources 1

About this happening: AmnesiaStealer is a Rust-based macOS infostealer spread through a counterfeit GitHub "Download for macOS" page and ClickFix-style lure. It steals Keychain, b...

ClickFix AmnesiaStealer distribution campaign targeting mac users

Campaign
H score22 First: 14.08.2026 13:45 Last: 14.08.2026 13:45 Sources 1

About this happening: A ClickFix campaign is distributing AmnesiaStealer to macOS users through a counterfeit GitHub "Download for macOS" page and a copy-and-paste command that launches...

Latest development: 16.08.2026 18:07

Jamf described AmnesiaStealer's stream_module and remote_stream commands, which copy a victim's Chromium profile into a hidden headless browser and open WebSocket and Chrome DevTools Protocol channels through webSocketDebuggerUrl. The operator can issue navigation and mouse commands, receive live screencasts, and export or import cookies to operate online portals inside the victim's authenticated sessions on Google Chrome, Microsoft Edge, Vivaldi, Arc, Opera, Brave, and Chromium.

Go-based macOS stealer with DRAIN wallet-draining routine

Malware Activity
H score29 First: 07.08.2026 21:29 Last: 07.08.2026 21:29 Sources 1

How related: What's notable about the malware is that it also packs in a "DRAIN" routine that checks if a cryptocurrency wallet holds funds, and if so, redirects a chunk or all of it to an attacker-controlled wallet.

About this happening: A Go-based macOS stealer delivered through ClickFix-style attacks is stealing browser passwords, Apple iCloud Keychain data, and cached credentials while also...

ClickFix Go-based macOS infostealer and crypto drainer

Malware Activity
H score29 First: 07.08.2026 01:37 Last: 07.08.2026 01:37 Sources 1

How related: ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials.

About this happening: A Go-based malware delivered through ClickFix is targeting macOS users to steal cryptocurrency assets, browser-stored passwords, Apple iCloud Keychain data...

Timeline

  1. 07.08.2026 01:37 4 articles · 13d ago

    ClickFix delivers a macOS infostealer that steals Apple Keychain data and crypto assets

    Technical Analysis Update

    A Go-based malware delivered through ClickFix lures against macOS users uses an email link to a page that instructs the victim to run a command in Terminal, then drops a Bash profiler and loader plus a matching Mach-O payload. The malware steals browser-stored passwords, Apple Keychain data, cached credentials, and cryptocurrency assets, can alter transactions before signing to divert funds, and uses com.apple.verified together with a removed com.apple.quarantine attribute to evade Gatekeeper. It also communicates with shared IP addresses in AS 210644 linked to the Aeza Group.

    Show sources