NewsLayer

Install NewsLayer

Get the app experience — one tap from your home screen, instant loads and breaking-news alerts.

Enjoying NewsLayer?

Get breaking crypto stories the second they drop — join our Telegram channel.

NewsLayer.com

Go-Based macOS Malware Steals Crypto and Secrets

Publicado há um dia 1 min de leitura
Go-Based macOS Malware Steals Crypto and Secrets

Infosecurity Magazine reports on Go-based malware targeting macOS users to steal cryptocurrency and sensitive information. The malware highlights ongoing risks to digital wallets and personal secrets on Apple devices.

Pontos-Chave

  • 01 A Go-based malware strain is targeting macOS systems.
  • 02 The malware is designed to steal cryptocurrency and sensitive information.
  • 03 Mac users with crypto assets remain a target for credential- and wallet-focused threats.

Security researchers have discovered new infostealing macOS malware delivered via ClickFix social engineering attacks.

Managed detection and response (MDR) specialist Huntress said that it came across the malware in June 2026.

“In a ClickFix attack, the computer's user is presented with a popup window that appears to be a form of CAPTCHA prompt,” it noted.

“The window instructs the target to copy the text of a long command string and to paste it into the Terminal application on the computer. The command string typically downloads and executes the initial stage of the attack.”

Read more on ClickFix: ClickFix Attacks Surge 517% in 2025

In this particular attack, the command pulled a Bash profiler/loader that collected system details, then fetched a Mac-native Mach-O payload matched to the victim's processor architecture.

“Mach-O is the executable format used by macOS, and in this case the Go-based stealer was built to scrape browser password stores, Apple Keychain data, and cached credentials from the infected system,” the blog post continued.

“The malware also included a DRAIN function that could check whether a cryptocurrency wallet held funds, then redirected all or part of that balance to attacker-controlled wallets.”

The loader, payload hosting and command and control (C2) all link back to the Aeza Group, a sanctioned Russian bulletproof hoster associated with cybercrime.

Huntress advised organizations to mitigate ClickFix threats through user education and by installing malicious script mitigation browser add-ons like NoScript. It added that network devices like Pi-Hole DNS can reduce the chances of popups appearing by blocking known-bad domains from resolving through DNS blocking.

“If a user inadvertently follows through with a ClickFix exploit, it is imperative that the user inform their IT team immediately and that the machine be brought into an isolation mode,” it concluded.

“The malware may or may not achieve persistence, but it is easily remediated by deleting any copies of the binary left behind on the machine. Once deleted, the malware will not spontaneously reconstitute itself.”

Attribution

Originally reported by Infosecurity Magazine

Respostas Rápidas

What does the Go-based macOS malware steal?

According to the excerpt, it steals cryptocurrency and sensitive information, described as secrets.

Which devices are targeted by this malware?

The malware targets systems running macOS.

Why is this malware relevant to crypto users?

It is relevant because the malware is reported to steal cryptocurrency, potentially putting users' digital assets at risk.

Get stories like this, daily.

Daily crypto + regulation intelligence, straight to your inbox. Free.

Notícias Relacionadas