Go-based macOS stealer with DRAIN wallet-draining routine
Malware Activity
Summary
Hide ▲
Show ▼
A Go-based macOS stealer delivered through ClickFix-style attacks is stealing browser passwords, Apple iCloud Keychain data, and cached credentials while also siphoning cryptocurrency from infected wallets. The malware's DRAIN routine increases financial risk for macOS users by redirecting wallet contents to attacker-controlled accounts.
Related Happenings
MacSync Stealer rotating-domain exfiltration activity
Malware Activity
H score30
First: 19.08.2026 09:01
Last: 19.08.2026 09:01
Sources 1
About this happening:
The MacSync Stealer operation has been tied to 30+ rotating domains and confirmed active data exfiltration, increasing the risk of credential theft on macOS endpoi...
MacSync Stealer rotating-domain exfiltration activity
Malware ActivityAbout this happening: The MacSync Stealer operation has been tied to 30+ rotating domains and confirmed active data exfiltration, increasing the risk of credential theft on macOS endpoi...
AmnesiaStealer macOS infostealer distributed via ClickFix
Malware Activity
H score16
First: 14.08.2026 13:45
Last: 14.08.2026 13:45
Sources 1
About this happening:
AmnesiaStealer is a Rust-based macOS infostealer spread through a counterfeit GitHub "Download for macOS" page and ClickFix-style lure. It steals Keychain, b...
AmnesiaStealer macOS infostealer distributed via ClickFix
Malware ActivityAbout this happening: AmnesiaStealer is a Rust-based macOS infostealer spread through a counterfeit GitHub "Download for macOS" page and ClickFix-style lure. It steals Keychain, b...
ClickFix macOS Terminal-command lure campaign
Campaign
H score42
First: 07.08.2026 01:37
Last: 07.08.2026 01:37
Sources 1
How related:
The attack chain begins with pasting a ClickFix command into the Terminal app, triggering the execution of a Bash profiler/loader that collects extensive system details and then retrieves a Mach-O payload that matches the victim's processor architecture.
About this happening:
The ClickFix campaign is delivering a Go-based macOS stealer through Terminal commands pasted from lure pages, creating a path to browser password theft, Apple K...
ClickFix macOS Terminal-command lure campaign
CampaignHow related: The attack chain begins with pasting a ClickFix command into the Terminal app, triggering the execution of a Bash profiler/loader that collects extensive system details and then retrieves a Mach-O payload that matches the victim's processor architecture.
About this happening: The ClickFix campaign is delivering a Go-based macOS stealer through Terminal commands pasted from lure pages, creating a path to browser password theft, Apple K...
ClickFix Go-based macOS infostealer and crypto drainer
Malware Activity
H score29
First: 07.08.2026 01:37
Last: 07.08.2026 01:37
Sources 1
How related:
ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials.
About this happening:
A Go-based malware delivered through ClickFix is targeting macOS users to steal cryptocurrency assets, browser-stored passwords, Apple iCloud Keychain data...
ClickFix Go-based macOS infostealer and crypto drainer
Malware ActivityHow related: ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials.
About this happening: A Go-based malware delivered through ClickFix is targeting macOS users to steal cryptocurrency assets, browser-stored passwords, Apple iCloud Keychain data...
PylangGhost and GolangGhost ClickFix RAT delivery on Windows and macOS
Malware Activity
H score29
First: 21.07.2026 12:30
Last: 21.07.2026 12:30
Sources 1
About this happening:
The PylangGhost and GolangGhost malware operation now uses ClickFix interview portals to install remote access trojans on Windows and macOS, putting Web3 a...
PylangGhost and GolangGhost ClickFix RAT delivery on Windows and macOS
Malware ActivityAbout this happening: The PylangGhost and GolangGhost malware operation now uses ClickFix interview portals to install remote access trojans on Windows and macOS, putting Web3 a...
Timeline
-
07.08.2026 21:29 2 articles · 13d ago
ClickFix-style attacks deliver a Go-based macOS stealer that drains crypto wallets
Initial DisclosureClickFix-style attacks deliver a Go-based macOS stealer to macOS users through a pasted command in the Terminal app that launches a Bash profiler/loader, fetches a Mach-O payload matched to the victim's CPU architecture, steals browser passwords, Apple Keychain data, and cached credentials, and includes a DRAIN routine that can redirect cryptocurrency funds to an attacker-controlled wallet. The malicious payload staging and command-and-control infrastructure link back to Aeza Group, a Russian bulletproof hosting provider sanctioned by the U.S., the U.K., and Australia.
Show sources
- ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets — thehackernews.com — 07.08.2026 21:29
- ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets — thehackernews.com — 07.08.2026 21:29