
ClickFix macOS malware drains crypto wallets and steals credentials
A Go-based malware delivered through ClickFix phishing emails targets macOS users to steal cryptocurrency assets, browser passwords, and Apple Keychain data, and can intercept or redirect crypto transactions. It uses a Bash profiler and loader to load a Mach-O payload, hides itself by copying as com.apple.verified and removing quarantine attributes, and establishes persistence via fake prompts to grab credentials. The malware can modify transactions before signing, potentially draining only a percentage of funds across assets like Bitcoin, Ethereum, XRP, Monero, Litecoin, and Dogecoin. C2 traffic points to Aeza Group infrastructure (AS 210644), a sanctioned bulletproof-hosting provider.


