New MacOS Malware Exposed: A Threat to Cryptocurrency Wallets
In a significant cybersecurity revelation, researchers from Huntress have identified a sophisticated strain of malware targeting macOS systems, specifically designed to siphon funds from victims’ cryptocurrency wallets. This alarming discovery stems from an investigation into a fraudulent CAPTCHA scheme known as ClickFix, which has increasingly ensnared unsuspecting users.
The incident was uncovered during a retrospective threat analysis conducted in June 2026. A dedicated Huntress analyst traced a prior infection on a user’s system that had occurred three months earlier, revealing the insidious nature of the attack. The victim had been tricked into believing they were completing a routine CAPTCHA challenge, only to be presented with a pop-up that prompted them to copy and execute a command in the Mac Terminal application. This type of social engineering has gained traction in recent years, illustrating the evolving tactics employed by cybercriminals.
Upon executing the command, the malware began its destructive course. It utilized a Bash loader that performed a fingerprinting process on the machine, gathering essential system information before downloading a malicious Go-based Mach-O payload specifically crafted for the device’s architecture. The malware’s primary function was to harvest sensitive information, such as credentials from the Apple Keychain, browser password stores, and cached cookies. To evade scrutiny, the malware cleverly disguised itself within a folder that mimicked a legitimate Apple system process and removed its quarantine flag—a precaution that would ordinarily prompt a Gatekeeper security warning.
Huntress highlighted a particularly disturbing feature of this malware, known as the DRAIN function. This capability allows the malware to assess the balance of any detected cryptocurrency wallet. If a balance is found, the malware can transfer a predetermined percentage or the entire amount to a wallet controlled by the attackers. The code was not only versatile but specifically designed to work with several cryptocurrencies, including Bitcoin, Litecoin, Dogecoin, Ethereum, and XRP. Moreover, the malware included variables that calculated the dollar value of a wallet’s contents, enabling the attackers to drain the funds gradually. This tactic prevents detection that could arise from a sudden and complete draining of assets, an approach that has not been previously observed in such malware.
Further examination of the malware revealed additional social engineering techniques. The attackers employed an osascript-generated dialog box to trick the victim into re-entering their system password, thereby granting the malware elevated privileges without raising alarms. This manipulative strategy underscores the lengths to which cybercriminals will go to exploit their victims.
Investigators at Huntress conducted an infrastructure analysis that revealed links between the malware’s loader, its payload hosting, and a command-and-control server associated with Aeza Group, a notorious Russian bulletproof hosting provider. The US Treasury’s Office of Foreign Assets Control sanctioned Aeza Group in July 2025, with the UK and Australia implementing further sanctions against ransomware-supporting infrastructure a few months later. This connection suggests a broader network of criminal activity aimed at exploiting vulnerable systems.
In response to these findings, Huntress has urged organizations to regard ClickFix-style prompts as potential red flags. The firm recommends comprehensive training for employees, emphasizing the importance of never entering unknown commands into a terminal window. Moreover, they advocate for the use of malicious-script mitigation browser extensions and implementing DNS-level blocking of known bad domains. Immediate isolation of any machine where a ClickFix command has been executed is also advised to curb potential damages.
As part of their commitment to cybersecurity, Huntress has made available various indicators of compromise, including file hashes and associated IP addresses, through their GitHub threat-intelligence repository. This proactive approach aims to arm users and organizations with the necessary tools to defend against such threats.
For those wishing to delve deeper into this troubling development, additional information and insights can be found on Huntress’s official blog here.
The implications of this discovery highlight the urgent need for enhanced vigilance within the cybersecurity landscape, particularly as cybercriminal tactics continue to evolve and become more sophisticated. As organizations strive to protect sensitive information, the potential for malicious actors to exploit vulnerabilities in seemingly innocuous tasks has never been more apparent.