Mac Malware Drains Crypto Wallets Via Fake CAPTCHA Scam
Cybersecurity Classified by Officially
The root cause of the macOS malware infection was a ClickFix scam.
The ClickFix attack delivered a shell script that collects profiling information about the computer, then retrieves a macOS malware payload that varies based on the computer's CPU architecture.
While the malware payload is capable of stealing passwords, its most interesting function is its capability to slowly deplete cryptocurrency accounts, siphoning their contents into accounts under the threat actor's control.
The IP address range that hosted the malware belongs to a known Russian bulletproof hosting provider that was sanctioned by the US and other countries in 2025.
Acknowledgments: Special thanks to Anna Pham, Bryan Masters, and Jai Minton for their contributions to this investigation, improvements to detection signals, and write-up.
TL;DR: Huntress responded to an incident where the target was tricked into pasting a ClickFix command into a Mac Terminal. The target infected their macOS device with a Go-based Mach-O (the native application format for Mac computers) malware, which was delivered as the final payload of a chain of shell scripts the ClickFix command downloaded. The malware collects sensitive credentials from the macOS Keychain and other applications, and exfiltrates them to an external address.
During a retrospective threat hunt in June 2026, a Huntress analyst found components of a Mac-specific stealer malware on a monitored system that had been infected three months earlier.
This is an extract. The publication continues at the source.
Read the original at the source: https://www.huntress.com/blog/mac-crypto-draining-malware
Officially imported this from Huntress’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- Huntress — imported from official source
- Official source
- https://www.huntress.com/blog/rss.xml RSS
- Imported
- September 20, 2026 19:55
- Versions
- 1 recorded
- Identity
https://www.huntress.com/blog/mac-crypto-draining-malware