← Blog · · df00tech

ClickFix Attack Delivers Go-Based macOS Infostealer Targeting Crypto Wallets and Keychain Data

security-news campaign

What happened

According to BleepingComputer, a Go-based malware family is being distributed via ClickFix-style attacks targeting macOS users. Once installed, the malware reportedly steals cryptocurrency assets, browser-stored passwords, Apple Keychain data, and cached credentials.

Why it matters

ClickFix is a social-engineering delivery technique that tricks users into copying and pasting attacker-supplied commands into a terminal or "Run" dialog, typically under the guise of fixing an error or verifying a CAPTCHA. Its use here against macOS — a platform users often assume is less targeted — broadens the attack surface for this technique beyond the Windows-focused ClickFix campaigns seen previously. The reported theft of Apple Keychain data and browser credentials, on top of crypto assets, means a successful infection could lead to both direct financial loss and downstream account compromise across other services.

Who's affected

macOS users, with particular relevance to individuals and organizations holding cryptocurrency assets on the affected machines.

What defenders should watch for

  • User-reported instances of being instructed to paste and run terminal commands from a webpage, error prompt, or CAPTCHA-style verification page.
  • Unusual outbound network activity or process execution originating from Terminal.app or similar shells shortly after a browser session, which may indicate a ClickFix-style pastejack execution.
  • Unexpected access to Keychain data or browser credential stores by unrecognized processes.
  • General user awareness: no legitimate site or software fix requires copying a command into Terminal to resolve an error or pass a CAPTCHA.
  • Review endpoint logging and Gatekeeper/XProtect status on macOS fleets, and ensure users are cautioned against following such prompts.

Because this is Go-based malware, defenders may also want to watch for statically compiled, cross-platform-style binaries executing from user-writable directories as a general hunting heuristic, pending further technical detail from the source.

Developing story

Specific indicators of compromise, the malware's name/family attribution, and full technical detail were not included in the available reporting at time of writing. This is net-new intelligence and this post will be updated as more detail emerges. Read the original report at BleepingComputer.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.