Researchers at Huntress have uncovered a pressure of macOS malware that may regularly siphon funds out of victims’ cryptocurrency wallets, after tracing an an infection again to a pretend CAPTCHA rip-off often known as ClickFix.
The incident got here to gentle throughout a retrospective risk hunt in June 2026, when a Huntress analyst found remnants of a Mac-specific stealer on a system that had really been compromised three months earlier. The sufferer had been served a pop-up disguised as a routine CAPTCHA examine, instructing them to repeat a command and paste it into the Mac Terminal utility – a social engineering method the safety vendor says has surged in recognition lately.
As soon as executed, the command quietly pulled down a Bash loader that fingerprinted the machine earlier than fetching a Go-based Mach-O payload tailor-made to the machine’s processor structure. The malware was constructed to reap credentials from the Apple Keychain, browser password shops and cached browser cookies. To keep away from detection, it wrote itself right into a folder disguised as a reputable Apple system course of and stripped the file of the quarantine flag that will usually set off a Gatekeeper safety warning.
The malware’s standout function, in keeping with Huntress, is a operate it calls DRAIN, which checks whether or not a detected cryptocurrency pockets holds a stability and, in that case, transfers both a set proportion or your complete quantity to a pockets managed by the attacker. The code included devoted routines for Bitcoin, Litecoin, Dogecoin, Ethereum and XRP, together with variables to calculate what a given proportion of a pockets’s contents could be value – permitting operators to bleed a pockets dry incrementally reasonably than emptying it in a single apparent transaction. Huntress famous that is the primary time it had noticed wallet-draining malware constructed to take away a managed fraction of funds reasonably than the total stability outright.
Investigators additionally discovered the attackers used an osascript-generated dialogue field to trick the sufferer into re-entering their system password, granting the malware elevated privileges with out elevating suspicion.
Infrastructure evaluation tied the loader, payload internet hosting and command-and-control server to IP deal with ranges operated by Aeza Group, a Russian bulletproof internet hosting supplier. Aeza Group was sanctioned by the US Treasury’s Workplace of International Belongings Management in July 2025, with the UK and Australia becoming a member of an extra spherical of sanctions in opposition to ransomware infrastructure suppliers in November 2025.
Huntress is urging organisations to deal with ClickFix-style prompts as a crimson flag and to coach employees by no means to stick unknown instructions right into a terminal window. The agency additionally recommends malicious-script mitigation browser extensions and DNS-level blocking of known-bad domains as extra layers of defence, alongside speedy isolation of any machine the place a ClickFix command has been run.
The corporate has revealed indicators of compromise, together with file hashes and the IP addresses concerned, through its GitHub threat-intelligence repository.
You possibly can learn extra right here: https://www.huntress.com/weblog/mac-crypto-draining-malware






