Mac Malware Found Draining Crypto Wallets After Fake CAPTCHA Trick
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
Huntress researchers have uncovered a macOS malware strain that uses a fake CAPTCHA (ClickFix) trick to get victims to paste a malicious command into Terminal. Once executed, a Bash loader fetches a Go-based payload that harvests Apple Keychain credentials, browser passwords, and cookies. Its standout feature is a DRAIN function that incrementally siphons cryptocurrency wallet funds — covering Bitcoin, Litecoin, Dogecoin, Ethereum, and XRP — rather than emptying wallets all at once to avoid detection. The malware also tricks victims into re-entering their system password via a fake dialog box. Infrastructure was traced to Aeza Group, a sanctioned Russian bulletproof hosting provider. Huntress recommends treating ClickFix prompts as red flags, training staff not to paste unknown terminal commands, and using browser extensions and DNS-level blocking as defenses.