Huntress researchers have uncovered a new ClickFix-style attack campaign targeting macOS users with a Go-based stealer malware capable of stealing cryptocurrency, browser passwords, Apple iCloud Keychain data, and cached credentials. The infection chain begins when a victim is tricked into pasting a crafted command into the Terminal app, which executes a Bash profiler/loader that collects system details and fetches a Mach-O payload tailored to the victim’s CPU architecture.
The malware, which can escalate privileges via a fake system error prompt, includes a unique ‘DRAIN’ routine that checks if a cryptocurrency wallet holds funds and then redirects a portion or all of it to an attacker-controlled wallet. The routine supports multiple cryptocurrencies, including Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and Ripple’s XRP. Huntress noted this is the first time they have seen malware capable of emptying a wallet in such a targeted manner, with functions to calculate 1% of the wallet’s value.
The malicious infrastructure, including payload staging and command-and-control servers, is linked to Aeza Group, a Russian bulletproof hosting provider sanctioned by the U.S., U.K., and Australia. The disclosure coincides with other recent ClickFix campaigns, including one distributing MacSync and Atomic Stealer via look-alike domains, another abusing Windows’ Program Compatibility Assistant (pcalua.exe) to bypass heuristics, and a third using WebAssembly and steganography via SVG images to evade detection. Additionally, separate campaigns have been observed delivering Lumma Stealer via fake movie downloads and cracked software lures.
CVEs: CVE-2026-50522
Malware: Lumma Stealer, Atomic Stealer, MacSync, Remus
Companies: Huntress, Palo Alto Networks Unit 42, Aeza Group
Original source: thehackernews.com