Mac Malware Drains Crypto Wallets Via Fake CAPTCHA Scam
ID: 09443d19-fc83-5294-9d14-b9db7a32aef5
STIX ID: report--09443d19-fc83-5294-9d14-b9db7a32aef5
Feed Name: Huntress Blog
Huntress investigated a ClickFix social-engineering incident that tricked a macOS user into pasting a command into Terminal, which downloaded a Bash profiler/loader and an ARM64/x86_64 Go-based Mach-O stealer; the malware exfiltrated Keychain and browser credentials, could query and siphon cryptocurrency wallets (a "DRAIN" function), established persistence via LaunchAgents, and communicated with command-and-control and payload hosts within Aeza Group's bulletproof hosting IP space — the report includes detailed TTPs and IOCs (file paths, SHA256 hashes, IPs, domain, and port).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
