ClickFix attack pushes macOS infostealer for crypto theft attacks
Key Points:
- A Go-based malware delivered via ClickFix attacks on macOS targets cryptocurrency assets, browser-stored passwords, Apple Keychain data, and cached credentials, stealing sensitive information and intercepting crypto transactions.
- The malware can redirect a portion of cryptocurrency transactions to attackers rather than emptying wallets entirely, calculating transaction values to divert specific amounts.
- Discovered by Huntress MDR, the infection begins with a phishing email prompting the user to run a Terminal command that downloads a Bash script, which profiles the system and loads a Mach-O payload tailored to the victim's processor.
- The malware establishes persistence by mimicking macOS processes and removing quarantine attributes to evade security warnings, while using fake error dialogs to collect system credentials and escalate privileges.
- Targeted cryptocurrencies include Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and XRP, with the malware communicating to IP addresses linked to the Russian Aeza Group.