macOS Crypto Stealer Delivered via ClickFix Social Engineering
Attackers are using ClickFix-style social engineering to deliver macOS malware that steals crypto assets and credentials. The Go-based payload targets both Intel and Apple Silicon Macs.
TL;DR
- ClickFix attacks now deliver macOS malware written in Go
- Payload steals cryptocurrency wallets, passwords, and iCloud Keychain data
- Initial access uses shell script that detects CPU architecture
- Malware compatible with both Intel and Apple Silicon Macs
- Targets browser-stored credentials and cached authentication tokens
Cybercriminals have evolved their ClickFix social engineering tactics to target macOS users with sophisticated malware delivery. These attacks leverage deceptive messaging to trick victims into executing malicious scripts that profile their systems before downloading architecture-specific payloads.
The campaign represents a significant escalation in macOS-targeted threats, moving beyond simple phishing to deliver stealthy information stealers capable of harvesting high-value digital assets including cryptocurrency wallets and authentication credentials.
Attack Chain Breakdown
- Initial compromise begins with social engineering messages mimicking legitimate services
- Victims execute shell scripts that perform system reconnaissance
- Script identifies CPU architecture (Intel x86_64 or Apple ARM64)
- Architecture-specific Go malware downloaded from command-and-control infrastructure
- Execution bypasses standard security controls through legitimate system processes
Data Theft Capabilities
- Extracts private keys from popular cryptocurrency wallet applications
- Harvests browser-saved passwords and form data across major browsers
- Accesses iCloud Keychain stored credentials and tokens
- Steals cached credentials from development tools and cloud CLIs
- Exfiltrates collected data to attacker-controlled servers for monetization
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.