{"id":17509,"date":"2026-08-07T16:24:24","date_gmt":"2026-08-07T16:24:24","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=17509"},"modified":"2026-08-07T16:24:24","modified_gmt":"2026-08-07T16:24:24","slug":"mac-malware-discovered-draining-crypto-wallets-after-pretend-captcha-trick","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=17509","title":{"rendered":"Mac Malware Discovered Draining Crypto Wallets After Pretend CAPTCHA Trick"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p>Researchers at <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.huntress.com\/\">Huntress<\/a> have uncovered a pressure of macOS malware that may regularly siphon funds out of victims\u2019 cryptocurrency wallets, after tracing an an infection again to a pretend CAPTCHA rip-off often known as ClickFix.<\/p>\n<div class=\"jeg_ad jeg_ad_article jnews_content_inline_ads  \">\n<div class=\"ads-wrapper align-right \"><a rel=\"nofollow\" target=\"_blank\" href=\"http:\/\/bit.ly\/jnewsio\" aria-label=\"Visit advertisement link\" target=\"_blank\" rel=\"nofollow noopener\" class=\"adlink ads_image align-right\"><br \/>\n                                    <img decoding=\"async\" class=\"lazyload\" src=\"https:\/\/itsecguru.dessol.com\/wp-content\/uploads\/2018\/08\/ad_300x250.jpg\" alt=\"\" data-pin-no-hover=\"true\"\/><br \/>\n                                <\/a><\/div>\n<\/div>\n<p>The incident got here to gentle throughout a retrospective risk hunt in June 2026, when a Huntress analyst found remnants of a Mac-specific stealer on a system that had really been compromised three months earlier. The sufferer had been served a pop-up disguised as a routine CAPTCHA examine, instructing them to repeat a command and paste it into the Mac Terminal utility \u2013 a social engineering method the safety vendor says has surged in recognition lately.<\/p>\n<p>As soon as executed, the command quietly pulled down a Bash loader that fingerprinted the machine earlier than fetching a Go-based Mach-O payload tailor-made to the machine\u2019s processor structure. The malware was constructed to reap credentials from the Apple Keychain, browser password shops and cached browser cookies. To keep away from detection, it wrote itself right into a folder disguised as a reputable Apple system course of and stripped the file of the quarantine flag that will usually set off a Gatekeeper safety warning.<\/p>\n<p>The malware\u2019s standout function, in keeping with Huntress, is a operate it calls <strong>DRAIN<\/strong>, which checks whether or not a detected cryptocurrency pockets holds a stability and, in that case, transfers both a set proportion or your complete quantity to a pockets managed by the attacker. The code included devoted routines for Bitcoin, Litecoin, Dogecoin, Ethereum and XRP, together with variables to calculate what a given proportion of a pockets\u2019s contents could be value \u2013 permitting operators to bleed a pockets dry incrementally reasonably than emptying it in a single apparent transaction. Huntress famous that is the primary time it had noticed wallet-draining malware constructed to take away a managed fraction of funds reasonably than the total stability outright.<\/p>\n<p>Investigators additionally discovered the attackers used an osascript-generated dialogue field to trick the sufferer into re-entering their system password, granting the malware elevated privileges with out elevating suspicion.<\/p>\n<p>Infrastructure evaluation tied the loader, payload internet hosting and command-and-control server to IP deal with ranges operated by Aeza Group, a Russian bulletproof internet hosting supplier. Aeza Group was sanctioned by the US Treasury\u2019s Workplace of International Belongings Management in July 2025, with the UK and Australia becoming a member of an extra spherical of sanctions in opposition to ransomware infrastructure suppliers in November 2025.<\/p>\n<p>Huntress is urging organisations to deal with ClickFix-style prompts as a crimson flag and to coach employees by no means to stick unknown instructions right into a terminal window. The agency additionally recommends malicious-script mitigation browser extensions and DNS-level blocking of known-bad domains as extra layers of defence, alongside speedy isolation of any machine the place a ClickFix command has been run.<\/p>\n<p>The corporate has revealed indicators of compromise, together with file hashes and the IP addresses concerned, through its GitHub threat-intelligence repository.<\/p>\n<p>You possibly can learn extra right here: <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.huntress.com\/blog\/mac-crypto-draining-malware\">https:\/\/www.huntress.com\/weblog\/mac-crypto-draining-malware<\/a><\/p>\n<\/p><\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>Researchers at Huntress have uncovered a pressure of macOS malware that may regularly siphon funds out of victims\u2019 cryptocurrency wallets, after tracing an an infection again to a pretend CAPTCHA rip-off often known as ClickFix. The incident got here to gentle throughout a retrospective risk hunt in June 2026, when a Huntress analyst found remnants [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":17511,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[8814,662,10064,67,416,216,264,908],"class_list":["post-17509","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-captcha","tag-crypto","tag-draining","tag-fake","tag-mac","tag-malware","tag-trick","tag-wallets"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/17509","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=17509"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/17509\/revisions"}],"predecessor-version":[{"id":17510,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/17509\/revisions\/17510"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/17511"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=17509"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=17509"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=17509"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-08-07 18:14:36 UTC -->