ClickFix Malware Campaign Targets macOS Users with Crypto Wallet Stealer
A ClickFix malware campaign delivers a Go-based macOS stealer capable of stealing browser passwords, Apple Keychain data, and cryptocurrency wallet funds, with the malware's 'DRAIN' routine siphoning assets into attacker-controlled wallets. The attack chain is linked to Aeza Group, a sanctioned Russian hosting provider, and employs multiple evasion techniques to target macOS users.
ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials.
The macOS-focused infection chain is designed to deliver a shell script that profiles the host and then fetches a macOS malware payload that's compatible with the computer's CPU architecture.
"
*** END OF TRANSMISSION ***