Fake CAPTCHA ‘ClickFix’ Tricks Mac Users to Run Malware

Infosecurity Magazine · Medium sophistication
Last updated August 10, 2026

Researchers found macOS infostealer malware delivered through a fake CAPTCHA-style pop-up that convinces users to copy and paste a long command into the Terminal. The command downloads and runs a loader that steals browser passwords, Apple Keychain data, and can even drain cryptocurrency wallets to attacker-controlled addresses. Huntress links the hosting and command-and-control infrastructure to Aeza Group, a sanctioned Russian “bulletproof” hosting provider tied to cybercrime.

Key findings

  • The malware was delivered via ClickFix social engineering using a fake CAPTCHA-like pop-up.
  • Victims were instructed to copy a long command and paste it into macOS Terminal, which downloads and executes the first stage.
  • The loader collected system details, then fetched a Mac-native Mach-O payload matched to the victim’s CPU architecture.
  • The Go-based stealer scraped browser password stores, Apple Keychain data, and cached credentials.
  • A “DRAIN” function checked crypto wallet balances and redirected funds to attacker-controlled wallets.
  • Huntress linked hosting/loader/C2 to Aeza Group, described as a sanctioned Russian bulletproof hoster associated with cybercrime.
  • Huntress recommended user education, script-blocking browser add-ons (e.g., NoScript), DNS blocking (e.g., Pi-hole), and rapid IT reporting/isolation if a user runs the command.

Who’s being targeted

  • Commonly targeted roles: All employees (macOS users), Executives, Finance/Accounting, Developers/Engineering, IT Helpdesk and Desktop Support.
  • Affected industries: Cross-industry (organizations with macOS endpoints), Cryptocurrency holders/users.
  • Attack channels: website.
  • Impersonated: Website verification/CAPTCHA prompt.

Awareness takeaways

  • Train employees that no legitimate CAPTCHA or website ‘verification’ should ever require copying commands into Terminal.
  • If anyone runs a suspicious command, require immediate reporting and isolate the device quickly to limit damage.
  • Reduce exposure to malicious pop-ups by using script-blocking and DNS blocking controls where appropriate.
  • Communicate that these scams can lead to password and Keychain theft and even direct cryptocurrency loss.

Red flags to watch for

  • A CAPTCHA/website prompt should never require running Terminal commands
  • Instructions to copy/paste a “long command string” are a strong sign of a scam
  • The action results in downloading and executing software outside approved IT processes
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

On your Mac, a website suddenly shows a CAPTCHA-style popup that says: copy this long command into Terminal to fix access. This is a ClickFix attack. That command secretly downloads a Mac loader, then a Go-based stealer that raids your browser passwords, Apple Keychain, and even checks your crypto wallets to drain them. Here’s the aha: no real CAPTCHA or website verification ever needs you to open Terminal. If a site tells you to copy a long command, treat it like someone asking for your bank PIN. If you ever did paste a command from a website into Terminal, stop using that Mac and call IT immediately so they can isolate it before anything else is stolen.

Categories

Similar attacks

ClickFix Lure Drops Mac Stealer That Drains Crypto

ClickFix Lure Drops Mac Stealer That Drains Crypto

Researchers reported real-world ClickFix social engineering lures that trick macOS users into pasting a command into Terminal, which then installs a password- and keychain-stealing malware. The malware can also “slowly deplete” cryptocurrency wallets by redirecting funds to attacker-controlled…

August 7, 2026
Prompt Injection Hijacks AI Agents via “Normal” Repos

Prompt Injection Hijacks AI Agents via “Normal” Repos

The article describes how attackers can manipulate autonomous AI agents using “prompt injection,” including a Mozilla-tested proof-of-concept that hid malicious instructions inside an ordinary-looking code repository. When a developer’s AI coding agent processed and executed those instructions, it…

August 10, 2026
GitHub Issue Trick Turns AI Coders Against Repos

GitHub Issue Trick Turns AI Coders Against Repos

Researchers showed that a single public GitHub issue (from someone with no repo access) could steer popular AI coding agents into running dangerous commands, exposing tokens, and changing repositories. The risk comes from AI agents reading untrusted issue/PR text while also having access to…

August 6, 2026
Larva-24009 Lures Firms With Fake Doc Attachments

Larva-24009 Lures Firms With Fake Doc Attachments

AhnLab reports Larva-24009 has continued phishing campaigns through 2026, sending emails that trick employees into opening fake “document” attachments that are actually shortcut (LNK) files. When opened, the attachment runs hidden PowerShell commands, shows a decoy document, and silently downloads…

August 3, 2026
Fake Bank of America Email Pushes Hidden ScreenConnect

Fake Bank of America Email Pushes Hidden ScreenConnect

Attackers are impersonating Bank of America in mass phishing emails to pressure people into clicking a link “to avoid account restrictions.” Mac users are led to a fake login page that steals credentials and personal/financial data, while Windows users are tricked into installing a ScreenConnect…

August 5, 2026
Fake Bank of America Email Pushes Remote Access Tool

Fake Bank of America Email Pushes Remote Access Tool

Cybercriminals sent emails styled like Bank of America that redirected victims to fake pages and pushed a download called “Account Guard.” On Windows, the download installed ScreenConnect remote management software, giving attackers remote control of the device. The campaign used lookalike domains…

August 5, 2026