ClickFix macOS Terminal-command lure campaign
Campaign
Summary
Hide ▲
Show ▼
The ClickFix campaign is delivering a Go-based macOS stealer through Terminal commands pasted from lure pages, creating a path to browser password theft, Apple Keychain theft, cached-credential theft, and cryptocurrency diversion. The infection chain drops a Bash profiler/loader and then a Mach-O payload matched to the victim's CPU architecture. The malware uses a fake system prompt, com.apple.verified, and a removed com.apple.quarantine attribute to reduce warnings and prompt credential entry. Infrastructure tied to the activity includes AS 210644 and Aeza Group.
Related Happenings
MacSync Stealer rotating-domain exfiltration activity
Malware Activity
H score30
First: 19.08.2026 09:01
Last: 19.08.2026 09:01
Sources 1
About this happening:
The MacSync Stealer operation has been tied to 30+ rotating domains and confirmed active data exfiltration, increasing the risk of credential theft on macOS endpoi...
MacSync Stealer rotating-domain exfiltration activity
Malware ActivityAbout this happening: The MacSync Stealer operation has been tied to 30+ rotating domains and confirmed active data exfiltration, increasing the risk of credential theft on macOS endpoi...
AmnesiaStealer macOS infostealer distributed via ClickFix
Malware Activity
H score16
First: 14.08.2026 13:45
Last: 14.08.2026 13:45
Sources 1
About this happening:
AmnesiaStealer is a Rust-based macOS infostealer spread through a counterfeit GitHub "Download for macOS" page and ClickFix-style lure. It steals Keychain, b...
AmnesiaStealer macOS infostealer distributed via ClickFix
Malware ActivityAbout this happening: AmnesiaStealer is a Rust-based macOS infostealer spread through a counterfeit GitHub "Download for macOS" page and ClickFix-style lure. It steals Keychain, b...
ClickFix AmnesiaStealer distribution campaign targeting mac users
Campaign
H score22
First: 14.08.2026 13:45
Last: 14.08.2026 13:45
Sources 1
About this happening:
A ClickFix campaign is distributing AmnesiaStealer to macOS users through a counterfeit GitHub "Download for macOS" page and a copy-and-paste command that launches...
ClickFix AmnesiaStealer distribution campaign targeting mac users
CampaignAbout this happening: A ClickFix campaign is distributing AmnesiaStealer to macOS users through a counterfeit GitHub "Download for macOS" page and a copy-and-paste command that launches...
Latest development: 16.08.2026 18:07
Jamf described AmnesiaStealer's stream_module and remote_stream commands, which copy a victim's Chromium profile into a hidden headless browser and open WebSocket and Chrome DevTools Protocol channels through webSocketDebuggerUrl. The operator can issue navigation and mouse commands, receive live screencasts, and export or import cookies to operate online portals inside the victim's authenticated sessions on Google Chrome, Microsoft Edge, Vivaldi, Arc, Opera, Brave, and Chromium.
Go-based macOS stealer with DRAIN wallet-draining routine
Malware Activity
H score29
First: 07.08.2026 21:29
Last: 07.08.2026 21:29
Sources 1
How related:
What's notable about the malware is that it also packs in a "DRAIN" routine that checks if a cryptocurrency wallet holds funds, and if so, redirects a chunk or all of it to an attacker-controlled wallet.
About this happening:
A Go-based macOS stealer delivered through ClickFix-style attacks is stealing browser passwords, Apple iCloud Keychain data, and cached credentials while also...
Go-based macOS stealer with DRAIN wallet-draining routine
Malware ActivityHow related: What's notable about the malware is that it also packs in a "DRAIN" routine that checks if a cryptocurrency wallet holds funds, and if so, redirects a chunk or all of it to an attacker-controlled wallet.
About this happening: A Go-based macOS stealer delivered through ClickFix-style attacks is stealing browser passwords, Apple iCloud Keychain data, and cached credentials while also...
ClickFix Go-based macOS infostealer and crypto drainer
Malware Activity
H score29
First: 07.08.2026 01:37
Last: 07.08.2026 01:37
Sources 1
How related:
ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials.
About this happening:
A Go-based malware delivered through ClickFix is targeting macOS users to steal cryptocurrency assets, browser-stored passwords, Apple iCloud Keychain data...
ClickFix Go-based macOS infostealer and crypto drainer
Malware ActivityHow related: ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials.
About this happening: A Go-based malware delivered through ClickFix is targeting macOS users to steal cryptocurrency assets, browser-stored passwords, Apple iCloud Keychain data...
Timeline
-
07.08.2026 01:37 4 articles · 13d ago
ClickFix delivers a macOS infostealer that steals Apple Keychain data and crypto assets
Technical Analysis UpdateA Go-based malware delivered through ClickFix lures against macOS users uses an email link to a page that instructs the victim to run a command in Terminal, then drops a Bash profiler and loader plus a matching Mach-O payload. The malware steals browser-stored passwords, Apple Keychain data, cached credentials, and cryptocurrency assets, can alter transactions before signing to divert funds, and uses com.apple.verified together with a removed com.apple.quarantine attribute to evade Gatekeeper. It also communicates with shared IP addresses in AS 210644 linked to the Aeza Group.
Show sources
- ClickFix attack pushes macOS infostealer for crypto theft attacks — www.bleepingcomputer.com — 07.08.2026 01:37
- ClickFix attack pushes macOS infostealer for crypto theft attacks — www.bleepingcomputer.com — 07.08.2026 01:37
- ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets — thehackernews.com — 07.08.2026 21:29
- Go-Based macOS Malware Steals Crypto and Secrets — www.infosecurity-magazine.com — 10.08.2026 13:00