Overview
- Huntress published a technical analysis and IoCs on August 6, 2026, after finding a March infection during a June retrospective threat hunt.
- The infection begins when a victim pastes a ClickFix fake CAPTCHA command into Terminal which runs a Bash loader that profiles the Mac and downloads a processor-specific Go Mach-O payload.
- The payload harvests Apple Keychain entries, browser-stored passwords and cookies, uses osascript to show fake macOS dialogs to capture credentials, removes quarantine flags and registers a LaunchAgent for persistence.
- A novel DRAIN routine checks blockchain balances and can transfer either a configured percentage or the full amount from targeted wallets for Bitcoin, Ethereum, Litecoin, Dogecoin and XRP, though Huntress found no evidence the embedded attacker wallets received funds.
- Huntress links hosting and C2 infrastructure to IP ranges operated by Aeza Group, a sanctioned Russian bulletproof host, and urges isolating affected Macs, changing exposed credentials from trusted devices, replacing compromised wallets, deploying script-mitigation extensions and adding DNS-level blocking and ClickFix training.