ClickFix Attacks Deploy Advanced Crypto-Draining Stealers

The Rise of ClickFix Social Engineering on macOS A dangerous new wave of “ClickFix” attacks is currently targeting macOS users, delivering sophisticated Go-based malware designed to drain cryptocurrency wallets and harvest sensitive credentials. Traditionally seen in Windows environments, ClickFix-style attacks rely heavily on social engineering rather than exploiting software vulnerabilities. By tricking users into manually executing malicious commands, threat actors are bypassing native macOS security protocols, making this one of the most pressing endpoint security threats for Apple users today.

How the ClickFix Infection Chain Operates The attack typically begins when a user encounters a fake verification page or a deceptive “unexpected system error” prompt in their web browser. These pages instruct the victim to copy a specific command and paste it into the macOS Terminal application to resolve the fabricated issue. Executing this command triggers a Bash loader that profiles the victim’s hardware and software environment. It then reaches out to a remote server to fetch a Mach-O payload perfectly tailored to the system’s specific CPU architecture.

Advanced Credential Theft and Privilege Escalation Once the Go-based stealer is active on the machine, its primary goal is comprehensive data exfiltration. It targets browser-stored passwords, cached credentials, and deeply sensitive Apple iCloud Keychain data. To achieve this, the malware often mimics legitimate system UI prompts, tricking the user into typing their administrator password under the guise of repairing damaged system files. This grants the malware the elevated privileges it needs to deeply compromise the macOS environment and securely transmit the stolen data back to the attackers.

The “DRAIN” Routine: A Stealthy Crypto Threat According to Andrew Brandt, a security researcher at Huntress, the most alarming feature of this new macOS malware is its dedicated “DRAIN” routine. Instead of immediately emptying a discovered cryptocurrency wallet—which would quickly trigger alarms—the malware can be configured to slowly siphon funds. The malware contains specialized functions to calculate exactly 1% of a wallet’s total value, stealthily transferring small amounts of Bitcoin, Ethereum, Monero, Litecoin, or Dogecoin to attacker-controlled addresses over time.

Attribution and the Broader Threat Landscape Researchers have linked the command-and-control (C2) infrastructure for this campaign back to the Aeza Group, a sanctioned Russian bulletproof hosting provider known for facilitating cybercrime. This macOS campaign is part of a much larger surge in ClickFix methodologies. Palo Alto Networks’ Unit 42 recently documented parallel Windows attacks abusing the Program Compatibility Assistant (pcalua.exe) and utilizing WebAssembly modules with SVG image steganography to evade network detection. As cybercriminals increasingly rely on SEO poisoning, pirated software lures, and deceptive verification screens, user education remains the strongest defense against ClickFix attacks.

Privacy Preference Center