Tag

Keychain

All articles tagged with #keychain

ClickFix macOS malware drains crypto wallets and steals credentials
technology25 days ago

ClickFix macOS malware drains crypto wallets and steals credentials

A Go-based malware delivered through ClickFix phishing emails targets macOS users to steal cryptocurrency assets, browser passwords, and Apple Keychain data, and can intercept or redirect crypto transactions. It uses a Bash profiler and loader to load a Mach-O payload, hides itself by copying as com.apple.verified and removing quarantine attributes, and establishes persistence via fake prompts to grab credentials. The malware can modify transactions before signing, potentially draining only a percentage of funds across assets like Bitcoin, Ethereum, XRP, Monero, Litecoin, and Dogecoin. C2 traffic points to Aeza Group infrastructure (AS 210644), a sanctioned bulletproof-hosting provider.

Mac malware ClickLock Stealer tricks users into surrendering passwords with fake prompts
technology1 month ago

Mac malware ClickLock Stealer tricks users into surrendering passwords with fake prompts

Security researchers have detected ClickLock Stealer, a macOS malware that relies on social engineering rather than exploits: victims are duped into pasting a command into Terminal via a fake ClickFix/Cloudflare check, which then downloads modules and shows a fake progress bar. If users dismiss the password prompt, the system is locked; if they grant access to a Keychain item, the malware retrieves Chrome’s Safe Storage AES key to harvest passwords, cookies, password-manager data and crypto wallets, sending the data to a Telegram bot and installing a hidden backdoor. The campaign has been active since May 2026 across 33 countries, and Apple has added paste-warning protections in macOS Tahoe 26.4 to block pastes from suspicious sites.

Mac malware CrashStealer masquerades as Apple crash reporter to steal secrets
security1 month ago

Mac malware CrashStealer masquerades as Apple crash reporter to steal secrets

Jamf Threat Labs warns about CrashStealer, a macOS malware that pretends to be Apple’s crash reporting tool via a fake notarized app named Werkbit. It targets over 80 cryptocurrency wallet extensions and 14 password managers (such as 1Password, LastPass, and Dashlane), searches Documents and Downloads for data, and prompts for full-disk access and a system password to access the login keychain. The stolen data is encrypted with AES-256-GCM and sent to the attacker. Apple revoked Werkbit’s signing credentials, but the attack vector shows how notarization can be abused, and the threat could reappear; users should avoid apps that prompt for a password or claim to be CrashReporter.

CrashStealer macOS infostealer fakes Apple’s crash reporter to swipe credentials and crypto wallets
technology1 month ago

CrashStealer macOS infostealer fakes Apple’s crash reporter to swipe credentials and crypto wallets

A new macOS information-stealing malware named CrashStealer disguises itself as Apple’s CrashReporter to harvest Keychain data, browser credentials, and more than 80 crypto wallet extensions. Delivered via a signed, Apple-notarized dropper and launched with a fake system prompt, it exfiltrates encrypted data (AES-256-GCM) to a C2 server after collecting files from user directories. Researchers note its stealthy, self-re-signing persistence and its distinct client-side encryption and native C++ implementation, with the campaign gated behind a PIN and active since May 2026.