ClickFix attack pushes macOS infostealer for crypto theft attacks
Security researchers at Huntress discovered a Go-based malware delivered in ClickFix attacks targeting macOS users that steals cryptocurrency assets and other sensitive data.
Intelligence analysis by Qwen 2.5 (3B)

A new security threat involving the ClickFix attack has been uncovered, revealing a Go-based malware that targets macOS users. The malware steals cryptocurrency assets and other sensitive data such as browser passwords and Apple Keychain data.
A bad guy sent you an email with a link that tricked your computer into letting them steal things like passwords and money from your Apple phone.
Analysis
{"#infostealer-malware":"The infostealer malware used in this attack is a Go-based program that can intercept and redirect cryptocurrency transactions. It collects system information such as CPU and RAM usage, retrieves a Mach-O payload matching the victim's processor architecture, and creates a directory named after trustd to store stolen data.","#cryptocurrency-theft":"The malware targets various cryptocurrencies including Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and Ripple’s XRP. It can calculate the total value of transactions to determine how much to divert to the attacker and drain less than the total amount from victims' wallets.","#persistent-infection":"To establish persistence, the malware collects system credentials via a fake error created using the osascript utility. It also establishes persistence by modifying cryptocurrency transaction values before they are signed."}
Key points
- ClickFix attack targets macOS users with Go-based malware
- Malware steals cryptocurrency assets and sensitive data like passwords
- Establishes persistence by modifying transaction values before signing
- Targets various cryptocurrencies including Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and XRP
By improving security measures, we can prevent more attacks like this in the future. This will help keep people's personal information safe.
If not caught early, these types of attacks could cause a lot of damage to people’s finances and privacy.



