logo

Mac Malware Drains Crypto Wallets Via Fake CAPTCHA Scam

ID: 09443d19-fc83-5294-9d14-b9db7a32aef5

STIX ID: report--09443d19-fc83-5294-9d14-b9db7a32aef5

Feed Name: Huntress Blog

Threat Score
70/100

Date Published: 2026-08-06

Date Updated: 2026-08-19

...
...

Huntress investigated a ClickFix social-engineering incident that tricked a macOS user into pasting a command into Terminal, which downloaded a Bash profiler/loader and an ARM64/x86_64 Go-based Mach-O stealer; the malware exfiltrated Keychain and browser credentials, could query and siphon cryptocurrency wallets (a "DRAIN" function), established persistence via LaunchAgents, and communicated with command-and-control and payload hosts within Aeza Group's bulletproof hosting IP space — the report includes detailed TTPs and IOCs (file paths, SHA256 hashes, IPs, domain, and port).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.