Global Stock News

ClickFix attack pushes macOS infostealer for crypto theft attacks

ClickFix attack pushes macOS infostealer for crypto theft attacks

Go-based macOS infostealer hijacks cryptocurrency transactions

A Go-based malware delivered in ClickFix attacks targeting macOS users is stealing cryptocurrency assets, browser-stored passwords, Apple Keychain data, and cached credentials.

​The malware can intercept and redirect transactions with various cryptocurrencies. Although it can empty wallets entirely, it can also calculate the total value of a transaction to determine how much to divert to the attacker.

Security researchers at Managed Detection and Response (MDR) services company Huntress discovered the payload after responding to a ClickFix incident.

image

The targeted user received an email with a link to a page instructing them to run a command in Terminal.

This downloaded a Bash script acting as a profiler and…

Source link

Share this article

Scroll to Top