ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets

ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets — Ravie LakshmananAug 07, 2026Malware / Social Engineering [https://blogger.googleuserc

clickfix-attacks-deliver-macos-stealer-that-can-drain-crypto-wallets

What’s new: ClickFix attacks are being utilized to deliver a Go-based macOS malware that can steal cryptocurrency, browser passwords, and Apple iCloud Keychain data. The malware features a “DRAIN” routine that can deplete cryptocurrency wallets by redirecting funds to attacker-controlled accounts. The attack chain begins with a command pasted into the Terminal app, which executes a Bash script to profile the system and fetch the malware payload.

Who’s affected

macOS users, particularly those with cryptocurrency wallets, are at risk from this malware, which targets various cryptocurrencies including Bitcoin, Litecoin, and Ethereum.

What to do

  • Educate users about the risks of pasting commands into the Terminal from untrusted sources.
  • Implement endpoint protection solutions that can detect and block malicious scripts and payloads.
  • Regularly update software and systems to mitigate vulnerabilities that could be exploited by such malware.
  • Monitor cryptocurrency wallet activities for any unauthorized transactions.

Sources