ClickFix Lure Drops Mac Stealer That Drains Crypto

The Hacker News · High sophistication
Last updated August 7, 2026

Researchers reported real-world ClickFix social engineering lures that trick macOS users into pasting a command into Terminal, which then installs a password- and keychain-stealing malware. The malware can also “slowly deplete” cryptocurrency wallets by redirecting funds to attacker-controlled accounts, and it may prompt users with a fake system error to capture their macOS password.

Key findings

  • The ClickFix workflow relies on tricking victims into pasting a command into macOS Terminal, which runs a Bash profiler/loader and downloads a payload matched to the CPU architecture.
  • The Go-based macOS stealer can collect browser-stored passwords, Apple iCloud Keychain data, and cached credentials, and send them to a threat-actor server.
  • The malware includes a “DRAIN” routine to redirect cryptocurrency from victim wallets (including partial drains like ~1%).
  • The malware attempts to get higher privileges by showing a fake credential prompt framed as an “unexpected system error” and alleged system-file repair.
  • Infrastructure hosting payloads and C2 is linked to Aeza Group, described as a sanctioned “bulletproof hosting provider.”

Who’s being targeted

  • Commonly targeted roles: All employees (macOS users), Executives, Developers/Engineering, Finance (employees who manage crypto assets).
  • Affected industries: Technology (macOS users), Finance / Cryptocurrency users.
  • Attack channels: website, physical.
  • Impersonated: Website verification or support workflow (ClickFix-style lure), macOS system prompt / system repair process.

Awareness takeaways

  • Train users to never paste and run commands from a webpage or pop-up into Terminal (or Run boxes) without IT verification.
  • Treat unexpected credential prompts as suspicious, verify via a known internal support channel before entering a password.
  • Include crypto-asset protection in awareness training: wallet drains can be gradual and may not be obvious immediately.

Red flags to watch for

  • A website asking you to paste/run a command in Terminal is highly unusual
  • Instructions that bypass normal installers or IT processes
  • “Verification” steps that involve scripts/commands rather than standard login
  • A sudden password prompt tied to a vague “unexpected system error”
  • Pressure to enter credentials to “restore” files without an IT ticket or known change
  • Credential prompts appearing after running a copied/pasted command
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You land on a “verification” page and it says: “To continue, open Terminal and paste the following verification command.” Stop right there. This is a ClickFix-style lure. The moment you paste that into macOS Terminal, it runs a Bash loader that profiles your Mac and pulls down a Go-based stealer built for your CPU, grabbing browser passwords, iCloud Keychain data, and cached logins. Then it gets worse: the stealer can run a hidden “DRAIN” routine that slowly skims maybe 1% at a time from your cryptocurrency wallets, and it may pop up a fake macOS message, “Unexpected system error, enter your system password to restore damaged system files.” Your move: if any website tells you to paste a command into Terminal, don’t do it, screenshot it and send it to IT or support first. No screenshot, no Terminal.

Similar attacks

Fake CAPTCHA ‘ClickFix’ Tricks Mac Users to Run Malware

Fake CAPTCHA ‘ClickFix’ Tricks Mac Users to Run Malware

Researchers found macOS infostealer malware delivered through a fake CAPTCHA-style pop-up that convinces users to copy and paste a long command into the Terminal. The command downloads and runs a loader that steals browser passwords, Apple Keychain data, and can even drain cryptocurrency wallets to…

August 10, 2026
BengalSEO Tricks Bing Users Into Malware & Scam Calls

BengalSEO Tricks Bing Users Into Malware & Scam Calls

Researchers uncovered a long-running “SEO poisoning” operation that manipulates Bing search results to push people onto fake support and activation pages. Victims are steered through a chain of redirects to either download a malware-laced ZIP (MayaBot) or be pressured into calling a fake…

September 8, 2026
Fake Recruiters Push “Coding Tests” as RAT Traps

Fake Recruiters Push “Coding Tests” as RAT Traps

Researchers say the Iran-linked group Nimbus Manticore posed as recruiters on LinkedIn and job platforms to send developers “technical challenge” ZIP files that secretly installed cross-platform remote access trojans. The lures used urgency (short test windows) and realistic developer workflows…

September 1, 2026
CRPx0 Pushes Fake Updates to Trigger Ransomware

CRPx0 Pushes Fake Updates to Trigger Ransomware

Researchers say the CRPx0 cybercrime operation uses “ClickFix” lures (fake Windows Update and fake Google reCAPTCHA pages) to trick people into running commands that install ransomware. The group also advertises a white-label ransomware service and claims its victim count rose sharply, with data…

August 27, 2026
Fake GitHub Lure Tricks macOS Users Into Stealer

Fake GitHub Lure Tricks macOS Users Into Stealer

Researchers described AmnesiaStealer, a macOS info-stealer spread through a counterfeit “Download for macOS” page that tricks users into pasting a command into Terminal. The malware steals passwords and browser session data, and can even give an attacker live, hidden control of the victim’s browser…

August 17, 2026
ClickFix Sites Trick Macs Into Running Malware Commands

ClickFix Sites Trick Macs Into Running Malware Commands

A real ClickFix campaign used 250+ lookalike domains and browser fingerprinting to show malware lures mainly to real macOS visitors while showing harmless decoys to scanners and researchers. Victims were pushed to copy and run an obfuscated command in macOS Terminal, which then downloaded and…

August 6, 2026