ClickFix Lure Drops Mac Stealer That Drains Crypto

The Hacker News · High sophistication
Last updated August 7, 2026

Researchers reported real-world ClickFix social engineering lures that trick macOS users into pasting a command into Terminal, which then installs a password- and keychain-stealing malware. The malware can also “slowly deplete” cryptocurrency wallets by redirecting funds to attacker-controlled accounts, and it may prompt users with a fake system error to capture their macOS password.

Key findings

  • The ClickFix workflow relies on tricking victims into pasting a command into macOS Terminal, which runs a Bash profiler/loader and downloads a payload matched to the CPU architecture.
  • The Go-based macOS stealer can collect browser-stored passwords, Apple iCloud Keychain data, and cached credentials, and send them to a threat-actor server.
  • The malware includes a “DRAIN” routine to redirect cryptocurrency from victim wallets (including partial drains like ~1%).
  • The malware attempts to get higher privileges by showing a fake credential prompt framed as an “unexpected system error” and alleged system-file repair.
  • Infrastructure hosting payloads and C2 is linked to Aeza Group, described as a sanctioned “bulletproof hosting provider.”

Who’s being targeted

  • Commonly targeted roles: All employees (macOS users), Executives, Developers/Engineering, Finance (employees who manage crypto assets).
  • Affected industries: Technology (macOS users), Finance / Cryptocurrency users.
  • Attack channels: website, physical.
  • Impersonated: Website verification or support workflow (ClickFix-style lure), macOS system prompt / system repair process.

Awareness takeaways

  • Train users to never paste and run commands from a webpage or pop-up into Terminal (or Run boxes) without IT verification.
  • Treat unexpected credential prompts as suspicious, verify via a known internal support channel before entering a password.
  • Include crypto-asset protection in awareness training: wallet drains can be gradual and may not be obvious immediately.

Red flags to watch for

  • A website asking you to paste/run a command in Terminal is highly unusual
  • Instructions that bypass normal installers or IT processes
  • “Verification” steps that involve scripts/commands rather than standard login
  • A sudden password prompt tied to a vague “unexpected system error”
  • Pressure to enter credentials to “restore” files without an IT ticket or known change
  • Credential prompts appearing after running a copied/pasted command
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You land on a “verification” page and it says: “To continue, open Terminal and paste the following verification command.” Stop right there. This is a ClickFix-style lure. The moment you paste that into macOS Terminal, it runs a Bash loader that profiles your Mac and pulls down a Go-based stealer built for your CPU, grabbing browser passwords, iCloud Keychain data, and cached logins. Then it gets worse: the stealer can run a hidden “DRAIN” routine that slowly skims maybe 1% at a time from your cryptocurrency wallets, and it may pop up a fake macOS message, “Unexpected system error, enter your system password to restore damaged system files.” Your move: if any website tells you to paste a command into Terminal, don’t do it, screenshot it and send it to IT or support first. No screenshot, no Terminal.

Similar attacks

Fake CAPTCHA ‘ClickFix’ Tricks Mac Users to Run Malware

Fake CAPTCHA ‘ClickFix’ Tricks Mac Users to Run Malware

Researchers found macOS infostealer malware delivered through a fake CAPTCHA-style pop-up that convinces users to copy and paste a long command into the Terminal. The command downloads and runs a loader that steals browser passwords, Apple Keychain data, and can even drain cryptocurrency wallets to…

August 10, 2026
EvilTokens Uses Device Codes to Bypass MFA

EvilTokens Uses Device Codes to Bypass MFA

Microsoft reports that the EvilTokens phishing-as-a-service platform helped criminals compromise thousands of organizations by tricking users into completing a legitimate Microsoft “device code” login. The lure drives victims to enter a short code at microsoft.com/devicelogin, which unknowingly…

September 22, 2026
Fake LastPass Download on GitHub Drops Stealer

Fake LastPass Download on GitHub Drops Stealer

Researchers found attackers impersonating LastPass with a fake GitHub “LastPass Authenticator” download page that tricks people into downloading a large ZIP and running a fake installer. The installer uses a Microsoft-signed Windows driver to shut down antivirus/EDR tools, then runs a password…

September 21, 2026
Google Doc “Fix” Trick Delivers Malware

Google Doc “Fix” Trick Delivers Malware

A real-world social engineering attempt used a legitimate Google Doc to trick a target into manually running commands that installed malware. The attacker posed as a crypto marketing executive and used a fake “decryption failure” message and a “manual update” button as the lure, leading to an…

September 21, 2026
ClickFix Lures Spread ChainScript RAT

ClickFix Lures Spread ChainScript RAT

Researchers describe real-world “ClickFix” social-engineering lures that trick people into installing malware by downloading fake apps (like Spotify/Zoom/Teams) or copying commands into Terminal. One campaign abused a compromised, verified HBO Max Reddit account to run malicious ads, while another…

September 21, 2026
BengalSEO Tricks Bing Users Into Malware & Scam Calls

BengalSEO Tricks Bing Users Into Malware & Scam Calls

Researchers uncovered a long-running “SEO poisoning” operation that manipulates Bing search results to push people onto fake support and activation pages. Victims are steered through a chain of redirects to either download a malware-laced ZIP (MayaBot) or be pressured into calling a fake…

September 8, 2026