Particle.news
Download on the App Store

Mac Malware Uses ClickFix Fake CAPTCHA to Steal Passwords and Drain Crypto

Huntress says the Go-based infostealer includes a configurable DRAIN routine able to siphon a percentage of wallet funds with infrastructure tied to a sanctioned bulletproof host.

Overview

  • Huntress published a technical analysis and IoCs on August 6, 2026, after finding a March infection during a June retrospective threat hunt.
  • The infection begins when a victim pastes a ClickFix fake CAPTCHA command into Terminal which runs a Bash loader that profiles the Mac and downloads a processor-specific Go Mach-O payload.
  • The payload harvests Apple Keychain entries, browser-stored passwords and cookies, uses osascript to show fake macOS dialogs to capture credentials, removes quarantine flags and registers a LaunchAgent for persistence.
  • A novel DRAIN routine checks blockchain balances and can transfer either a configured percentage or the full amount from targeted wallets for Bitcoin, Ethereum, Litecoin, Dogecoin and XRP, though Huntress found no evidence the embedded attacker wallets received funds.
  • Huntress links hosting and C2 infrastructure to IP ranges operated by Aeza Group, a sanctioned Russian bulletproof host, and urges isolating affected Macs, changing exposed credentials from trusted devices, replacing compromised wallets, deploying script-mitigation extensions and adding DNS-level blocking and ClickFix training.