ClickFix Malware Targets macOS With Stealthy Crypto Draining

ClickFix Malware Targets macOS With Stealthy Crypto Draining

Rupert Marais is a leading voice in endpoint protection and device security, bringing years of experience in dissecting complex malware to the table. With a deep focus on the shifting landscape of macOS vulnerabilities, he specializes in identifying how social engineering intersects with technical exploits to bypass traditional defenses. Today, we discuss a sophisticated Go-based infostealer that utilizes the “ClickFix” strategy to compromise Mac users and siphons cryptocurrency with surgical, percentage-based precision.

How does the ClickFix campaign effectively manipulate macOS users into compromising their own systems?

The attack begins with a deceptive sense of urgency, often arriving via an email that directs the target to a fake support page. Users are instructed to copy and paste a specific command into their Terminal, a move that cleverly bypasses traditional browser-based security warnings. By framing this as a necessary “fix” for a supposed system error, the attackers leverage the user’s own manual actions to execute a malicious Bash script. Once that command is entered, the script begins profiling the machine’s hardware, checking CPU and RAM specs to ensure the next stage of the payload is perfectly tailored to that specific Mac’s architecture.

Once the initial script is executed, what technical maneuvers does the malware perform to hide from the operating system’s built-in defenses?

After the profiling stage, the malware downloads a Mach-O payload and places it in a newly created directory named after “trustd,” which is a legitimate macOS process responsible for validating certificates. By naming the file “com.apple.verified,” the attackers create a clever disguise that might fool a casual observer or a basic security sweep. Crucially, the script runs a command to remove the “com.apple.quarantine” extended attribute from the downloaded file. This specific action is designed to blindside Gatekeeper, preventing the OS from showing the standard security alert that usually triggers when a file is opened from an untrusted internet source.

In terms of data exfiltration, how does this malware gain access to highly sensitive areas like the Apple Keychain and browser-stored credentials?

To get the keys to the kingdom, the malware uses the “osascript” utility to trigger a fake system error dialog that looks indistinguishable from a legitimate macOS prompt. When the unsuspecting user enters their admin password to “fix” the error, the malware captures those credentials to escalate its privileges across the system. With that level of access, it begins scouring the storage for browser password databases, cookies, and the Apple Keychain itself. It doesn’t just stop at passwords; it searches for specific file extensions and cached data that can give the attackers full control over the victim’s digital identity.

The ability of this malware to drain specific percentages of cryptocurrency rather than emptying a wallet is quite unusual. How does this strategy benefit the attackers?

This is a chilling evolution in crypto-drainer logic where the malware can be configured to redirect only a fraction of the funds, such as 1% of the total wallet value. By modifying the transaction details before they are digitally signed, the attackers can skim money from assets like Bitcoin, Ethereum, or Ripple’s XRP without necessarily alerting the user through a massive balance drop. This “slow bleed” approach is a calculated move to remain undetected for longer periods compared to a total drain, which usually triggers immediate alarms. It shows a level of financial engineering where the malware calculates the value of that 1% based on the specific cryptocurrency type before redirecting it to the attacker’s address.

What do we know about the infrastructure supporting these attacks and the groups behind them?

The technical trail leads back to shared IP addresses within the Autonomous System 210644. This infrastructure is operated by a Russian corporation known as the Aeza Group, which has a notorious reputation for hosting malicious activity. The US and UK have already placed sanctions on this group and its affiliates for providing “bulletproof” hosting services that cater to various ransomware operations. Using such a resilient and protected infrastructure allows the malware to maintain a stable connection to its command-and-control servers, making it much harder for global authorities to disrupt the campaign.

What is your forecast for the evolution of macOS-specific threats over the next year?

I expect to see a significant rise in “living-off-the-land” techniques where attackers exploit built-in tools like Terminal and osascript to bypass the increasingly robust Gatekeeper protections. As more high-value targets and developers move to macOS, the sophistication of infostealers will likely mirror the complexity we’ve seen in the Windows ecosystem for years. We will likely see more malware written in cross-platform languages like Go, which allows developers to pivot their attacks between operating systems with minimal friction. Ultimately, the battle will shift toward user education, as the human element remains the most vulnerable entry point for social engineering tactics.

Subscribe to our weekly news digest.

Join now and become a part of our fast-growing community.

Invalid Email Address
Thanks for Subscribing!
We'll be sending you our best soon!
Something went wrong, please try again later