ClickFix Lure Drops Mac Stealer That Drains Crypto

The Hacker News · High sophistication
Last updated August 7, 2026

Researchers reported real-world ClickFix social engineering lures that trick macOS users into pasting a command into Terminal, which then installs a password- and keychain-stealing malware. The malware can also “slowly deplete” cryptocurrency wallets by redirecting funds to attacker-controlled accounts, and it may prompt users with a fake system error to capture their macOS password.

Key findings

  • The ClickFix workflow relies on tricking victims into pasting a command into macOS Terminal, which runs a Bash profiler/loader and downloads a payload matched to the CPU architecture.
  • The Go-based macOS stealer can collect browser-stored passwords, Apple iCloud Keychain data, and cached credentials, and send them to a threat-actor server.
  • The malware includes a “DRAIN” routine to redirect cryptocurrency from victim wallets (including partial drains like ~1%).
  • The malware attempts to get higher privileges by showing a fake credential prompt framed as an “unexpected system error” and alleged system-file repair.
  • Infrastructure hosting payloads and C2 is linked to Aeza Group, described as a sanctioned “bulletproof hosting provider.”

Who’s being targeted

  • Commonly targeted roles: All employees (macOS users), Executives, Developers/Engineering, Finance (employees who manage crypto assets).
  • Affected industries: Technology (macOS users), Finance / Cryptocurrency users.
  • Attack channels: website, physical.
  • Impersonated: Website verification or support workflow (ClickFix-style lure), macOS system prompt / system repair process.

Awareness takeaways

  • Train users to never paste and run commands from a webpage or pop-up into Terminal (or Run boxes) without IT verification.
  • Treat unexpected credential prompts as suspicious, verify via a known internal support channel before entering a password.
  • Include crypto-asset protection in awareness training: wallet drains can be gradual and may not be obvious immediately.

Red flags to watch for

  • A website asking you to paste/run a command in Terminal is highly unusual
  • Instructions that bypass normal installers or IT processes
  • “Verification” steps that involve scripts/commands rather than standard login
  • A sudden password prompt tied to a vague “unexpected system error”
  • Pressure to enter credentials to “restore” files without an IT ticket or known change
  • Credential prompts appearing after running a copied/pasted command
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You land on a “verification” page and it says: “To continue, open Terminal and paste the following verification command.” Stop right there. This is a ClickFix-style lure. The moment you paste that into macOS Terminal, it runs a Bash loader that profiles your Mac and pulls down a Go-based stealer built for your CPU, grabbing browser passwords, iCloud Keychain data, and cached logins. Then it gets worse: the stealer can run a hidden “DRAIN” routine that slowly skims maybe 1% at a time from your cryptocurrency wallets, and it may pop up a fake macOS message, “Unexpected system error, enter your system password to restore damaged system files.” Your move: if any website tells you to paste a command into Terminal, don’t do it, screenshot it and send it to IT or support first. No screenshot, no Terminal.

Similar attacks

ClickFix Sites Trick Macs Into Running Malware Commands

ClickFix Sites Trick Macs Into Running Malware Commands

A real ClickFix campaign used 250+ lookalike domains and browser fingerprinting to show malware lures mainly to real macOS visitors while showing harmless decoys to scanners and researchers. Victims were pushed to copy and run an obfuscated command in macOS Terminal, which then downloaded and…

August 6, 2026
Fake Bank of America Email Pushes Hidden ScreenConnect

Fake Bank of America Email Pushes Hidden ScreenConnect

Attackers are impersonating Bank of America in mass phishing emails to pressure people into clicking a link “to avoid account restrictions.” Mac users are led to a fake login page that steals credentials and personal/financial data, while Windows users are tricked into installing a ScreenConnect…

August 5, 2026
Fake Zoom/Adobe Updates Drop ScreenConnect Backdoor

Fake Zoom/Adobe Updates Drop ScreenConnect Backdoor

Researchers described an active phishing campaign that tricks people with fake Adobe/Zoom update and “document review” themes to install the legitimate ScreenConnect remote-access tool. Once installed, attackers get persistent remote control of the victim’s computer while blending in as normal IT…

August 4, 2026
Hijacked Hotel Wi‑Fi Tricks Travelers Into Logins

Hijacked Hotel Wi‑Fi Tricks Travelers Into Logins

Microsoft says a Russian-linked group is abusing hotel and conference Wi‑Fi “captive portals” to trick travelers into entering corporate credentials or installing malware. Victims see what looks like a normal Wi‑Fi login flow, but attackers manipulate DNS/website traffic to redirect them to fake…

August 4, 2026
Hijacked Hotel Wi‑Fi Serves Fake Updates

Hijacked Hotel Wi‑Fi Serves Fake Updates

Attackers hijacked hotel/captive-portal Wi‑Fi infrastructure to redirect travelers to fake browser or operating system update pages and trick them into installing spyware. The operation (tracked as CaptiveCrunch) used DNS manipulation and user prompts (including “ClickFix” instructions) to get…

August 1, 2026
Fake Zoom/Teams Calls Used to Steal Crypto Wallets

Fake Zoom/Teams Calls Used to Steal Crypto Wallets

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims into “updating” Zoom/Teams and running malicious commands. The phishing kit also fingerprints the victim’s browser to identify installed…

July 24, 2026