ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets
ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials. The macOS-focused infection chain is designed to deliver a shell script …
Intelligence analysis by Llama

A new ClickFix attack is being used to deliver a Go-based malware that can steal cryptocurrency assets, browser-stored passwords, and other sensitive information. The attack chain begins with pasting a ClickFix command into the Terminal app, triggering the execution of a Bash profiler/loader that collects extensive system details and then retrieves a Mach-O payload that matches the vi…
Imagine you're using a computer, and someone sneaks in a special kind of software that can steal your passwords and other secret information. This is what's happening with ClickFix attacks. The software is designed to look like a normal part of the computer, but it's actually sending your secrets to someone else's computer. It's like having a thief in your house, but instead of taking your valuables, they're taking your digital secrets.
Analysis
ClickFix Attacks: A Growing Threat to macOS Security
ClickFix-style attacks have been a growing concern in the cybersecurity community, and the latest variant is no exception. The attack chain begins with pasting a ClickFix command into the Terminal app, triggering the execution of a Bash profiler/loader that collects extensive system details and then retrieves a Mach-O payload that matches the victim's processor architecture.
The payload is a Go-based stealer that can capture browser passwords, Apple Keychain data, and cached credentials and transmit them to a remote server operated by the threat actor. Like other macOS stealers, the malware attempts to escalate privileges by prompting the victim to enter their system credentials via a fake prompt under the guise of an "unexpected system error" and restoring damaged system files.
What's notable about the malware is that it also packs in a "DRAIN" routine that checks if a cryptocurrency wallet holds funds, and if so, redirects a chunk or all of it to an attacker-controlled wallet. There exist multiple versions of the same function based on the cryptocurrency being targeted. This includes Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and Ripple's XRP.
"While this may not be a brand new feature, it's the first time we have seen malware capable of emptying a cryptocurrency wallet that could be used to remove any less than the entire wallet's value," Huntress said. "The malware contained separate functions to determine just how much 1% of the wallet's contents is worth, depending on which cryptocurrency the malware targets."
The server staging the malicious payloads and the command-and-control (C2) server all link back to infrastructure belonging to Aeza Group, a Russian bulletproof hosting provider that has been sanctioned by the U.S., the U.K., and Australia for facilitating bad actors.
The Role of Aeza Group in Facilitating Malware Distribution
Aeza Group, a Russian bulletproof hosting provider, has been linked to the distribution of the malware. The company has been sanctioned by the U.S., the U.K., and Australia for facilitating bad actors. The sanctions highlight the importance of taking action against companies that enable malicious activities.
The Impact of ClickFix Attacks on macOS Security
ClickFix attacks have been a growing concern for macOS security. The latest variant of the attack highlights the need for users to be vigilant and take steps to protect themselves from these types of attacks. The malware can capture sensitive information, including browser passwords, Apple Keychain data, and cached credentials, and transmit them to a remote server operated by the threat actor.
Conclusion
In conclusion, ClickFix attacks are a growing threat to macOS security. The latest variant of the attack highlights the need for users to be vigilant and take steps to protect themselves from these types of attacks. The malware can capture sensitive information and transmit it to a remote server operated by the threat actor. The server staging the malicious payloads and the command-and-control (C2) server all link back to infrastructure belonging to Aeza Group, a Russian bulletproof hosting provider that has been sanctioned by the U.S., the U.K., and Australia for facilitating bad actors.
Key points
- ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials.
- The macOS-focused infection chain is designed to deliver a shell script that profiles the host and then fetches a macOS malware payload that's compatible with the computer's CPU architecture.
- The malware attempts to escalate privileges by prompting the victim to enter their system credentials via a fake prompt under the guise of an "unexpected system error" and restoring damaged system files.
- The malware contains a "DRAIN" routine that checks if a cryptocurrency wallet holds funds, and if so, redirects a chunk or all of it to an attacker-controlled wallet.
- The server staging the malicious payloads and the command-and-control (C2) server all link back to infrastructure belonging to Aeza Group, a Russian bulletproof hosting provider that has been sanctioned by the U.S., the U.K., and Australia for facilitating bad actors.
If this development plays out positively, it could lead to increased awareness and vigilance among macOS users, which could help prevent future ClickFix attacks. Additionally, the sanctions against Aeza Group could lead to a decrease in the distribution of malware through their infrastructure.
The realistic downside risks or failure modes of this development include the potential for the malware to spread further and capture more sensitive information. Additionally, the sanctions against Aeza Group may not be effective in stopping the distribution of malware, and the threat actors may find alternative ways to operate.



