discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

ClickFix attack pushes macOS infostealer for crypto theft attacks

Security researchers at Huntress discovered a Go-based malware delivered in ClickFix attacks targeting macOS users that steals cryptocurrency assets and other sensitive data.

By Ionut Ilascu·Aug 6·bleepingcomputer.com·1 min read

Intelligence analysis by Qwen 2.5 (3B)

ClickFix attack pushes macOS infostealer for crypto theft attacks
Image: bleepingcomputer.com

A new security threat involving the ClickFix attack has been uncovered, revealing a Go-based malware that targets macOS users. The malware steals cryptocurrency assets and other sensitive data such as browser passwords and Apple Keychain data.

Why it matters

This discovery highlights the growing risk of cyber threats targeting macOS devices, emphasizing the importance of robust security measures for all operating systems.

A bad guy sent you an email with a link that tricked your computer into letting them steal things like passwords and money from your Apple phone.

Analysis

{"#infostealer-malware":"The infostealer malware used in this attack is a Go-based program that can intercept and redirect cryptocurrency transactions. It collects system information such as CPU and RAM usage, retrieves a Mach-O payload matching the victim's processor architecture, and creates a directory named after trustd to store stolen data.","#cryptocurrency-theft":"The malware targets various cryptocurrencies including Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and Ripple’s XRP. It can calculate the total value of transactions to determine how much to divert to the attacker and drain less than the total amount from victims' wallets.","#persistent-infection":"To establish persistence, the malware collects system credentials via a fake error created using the osascript utility. It also establishes persistence by modifying cryptocurrency transaction values before they are signed."}

Key points

  • ClickFix attack targets macOS users with Go-based malware
  • Malware steals cryptocurrency assets and sensitive data like passwords
  • Establishes persistence by modifying transaction values before signing
  • Targets various cryptocurrencies including Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and XRP
The Upside

By improving security measures, we can prevent more attacks like this in the future. This will help keep people's personal information safe.

The Downside

If not caught early, these types of attacks could cause a lot of damage to people’s finances and privacy.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritymacoscrypto-theftinfostealergolang

Author

Ionut Ilascu

Intelligence analysis by

Qwen 2.5 (3B)

Published

Aug 6, 2026

Source

bleepingcomputer.com

Share

Topics

securitymacoscrypto-theftinfostealergolang

Related

More from this desk

Aug 6·bleepingcomputer.com

OpenAI rolls out a major ChatGPT upgrade, even if you don’t pay for it

OpenAI has rolled out a major upgrade to its ChatGPT model, making it more direct, factually accurate, and consistent across quick questions and deeper reasoning tasks. The update includes a new slider that allows users to control the model's reasoning and intelligence.

Aug 6·bleepingcomputer.com

Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group

A recent wave of cyberattacks targeting hedge funds, private-equity firms, and other financial organizations has been linked to UNC6671, an extortion group reportedly associated with the BlackFile campaign extortion group.

Aug 6·bleepingcomputer.com

Swiss government SharePoint breach compromised 200 accounts

The Swiss government's federal IT office has been breached, with hackers exploiting vulnerabilities in Microsoft SharePoint servers to compromise approximately 200 accounts. The agency has blocked external internet access to SharePoint, patched the suspected vulnerabiliti…

Aug 6·thehackernews.com

New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts

A new Linux kernel vulnerability, tracked as CVE-2026-64561, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isolation and execute code on the host. The flaw affects KVM/x86's shadow memory management unit (MMU) and req…