Fake CAPTCHA ‘ClickFix’ Tricks Mac Users to Run Malware

Infosecurity Magazine · Medium sophistication
Last updated August 10, 2026

Researchers found macOS infostealer malware delivered through a fake CAPTCHA-style pop-up that convinces users to copy and paste a long command into the Terminal. The command downloads and runs a loader that steals browser passwords, Apple Keychain data, and can even drain cryptocurrency wallets to attacker-controlled addresses. Huntress links the hosting and command-and-control infrastructure to Aeza Group, a sanctioned Russian “bulletproof” hosting provider tied to cybercrime.

Key findings

  • The malware was delivered via ClickFix social engineering using a fake CAPTCHA-like pop-up.
  • Victims were instructed to copy a long command and paste it into macOS Terminal, which downloads and executes the first stage.
  • The loader collected system details, then fetched a Mac-native Mach-O payload matched to the victim’s CPU architecture.
  • The Go-based stealer scraped browser password stores, Apple Keychain data, and cached credentials.
  • A “DRAIN” function checked crypto wallet balances and redirected funds to attacker-controlled wallets.
  • Huntress linked hosting/loader/C2 to Aeza Group, described as a sanctioned Russian bulletproof hoster associated with cybercrime.
  • Huntress recommended user education, script-blocking browser add-ons (e.g., NoScript), DNS blocking (e.g., Pi-hole), and rapid IT reporting/isolation if a user runs the command.

Who’s being targeted

  • Commonly targeted roles: All employees (macOS users), Executives, Finance/Accounting, Developers/Engineering, IT Helpdesk and Desktop Support.
  • Affected industries: Cross-industry (organizations with macOS endpoints), Cryptocurrency holders/users.
  • Attack channels: website.
  • Impersonated: Website verification/CAPTCHA prompt.

Awareness takeaways

  • Train employees that no legitimate CAPTCHA or website ‘verification’ should ever require copying commands into Terminal.
  • If anyone runs a suspicious command, require immediate reporting and isolate the device quickly to limit damage.
  • Reduce exposure to malicious pop-ups by using script-blocking and DNS blocking controls where appropriate.
  • Communicate that these scams can lead to password and Keychain theft and even direct cryptocurrency loss.

Red flags to watch for

  • A CAPTCHA/website prompt should never require running Terminal commands
  • Instructions to copy/paste a “long command string” are a strong sign of a scam
  • The action results in downloading and executing software outside approved IT processes
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

On your Mac, a website suddenly shows a CAPTCHA-style popup that says: copy this long command into Terminal to fix access. This is a ClickFix attack. That command secretly downloads a Mac loader, then a Go-based stealer that raids your browser passwords, Apple Keychain, and even checks your crypto wallets to drain them. Here’s the aha: no real CAPTCHA or website verification ever needs you to open Terminal. If a site tells you to copy a long command, treat it like someone asking for your bank PIN. If you ever did paste a command from a website into Terminal, stop using that Mac and call IT immediately so they can isolate it before anything else is stolen.

Categories

Similar attacks

ClickFix Lure Drops Mac Stealer That Drains Crypto

ClickFix Lure Drops Mac Stealer That Drains Crypto

Researchers reported real-world ClickFix social engineering lures that trick macOS users into pasting a command into Terminal, which then installs a password- and keychain-stealing malware. The malware can also “slowly deplete” cryptocurrency wallets by redirecting funds to attacker-controlled…

August 7, 2026
Fake Minecraft Sites Keep Spreading WeedHack

Fake Minecraft Sites Keep Spreading WeedHack

Attackers are tricking Minecraft players into downloading malware by cloning legitimate mod/client websites and manipulating search results so the malicious pages appear highly ranked. Even after the malware’s command-and-control systems were disrupted, the fake sites and trusted file-hosting links…

September 8, 2026
APT28 Uses Diplomatic Word Lures to Drop HOOKEDGE

APT28 Uses Diplomatic Word Lures to Drop HOOKEDGE

Researchers report real-world campaigns targeting European government and diplomatic organizations using diplomatic-themed Microsoft Word documents. Victims are prompted to click “Enable Content,” which runs malicious macros that install the HOOKEDGE backdoor and connect to webhook-based…

August 28, 2026
Fake Minecraft Client Sites Still Push WeedHack

Fake Minecraft Client Sites Still Push WeedHack

Researchers report that the WeedHack malware campaign is still infecting people through convincing fake Minecraft client/mod websites, even after its command-and-control server was disrupted. Attackers use SEO poisoning and trusted community platforms (like Discord and Minecraft modding sites) to…

August 25, 2026
Fake GitHub Lure Spreads AmnesiaStealer on macOS

Fake GitHub Lure Spreads AmnesiaStealer on macOS

Researchers describe AmnesiaStealer, a macOS infostealer spread via a convincing fake GitHub download page that tricks users into pasting a Terminal command. After installation, it uses an “Installer”-style password prompt to capture the Mac login password, steal browser and keychain data, and can…

August 14, 2026
Prompt Injection Hijacks AI Agents via “Normal” Repos

Prompt Injection Hijacks AI Agents via “Normal” Repos

The article describes how attackers can manipulate autonomous AI agents using “prompt injection,” including a Mozilla-tested proof-of-concept that hid malicious instructions inside an ordinary-looking code repository. When a developer’s AI coding agent processed and executed those instructions, it…

August 10, 2026