International Cyber Expo International Cyber Expo
  • About Us
Sunday, 20 September, 2026
IT Security Guru
International Cyber Expo
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Mac Malware Found Draining Crypto Wallets After Fake CAPTCHA Trick

by Guru Writer
August 6, 2026
in News
Mac Malware Found Draining Crypto Wallets After Fake CAPTCHA Trick
Share on FacebookShare on Twitter

Researchers at Huntress have uncovered a strain of macOS malware that can gradually siphon funds out of victims’ cryptocurrency wallets, after tracing an infection back to a fake CAPTCHA scam known as ClickFix.

The incident came to light during a retrospective threat hunt in June 2026, when a Huntress analyst discovered remnants of a Mac-specific stealer on a system that had actually been compromised three months earlier. The victim had been served a pop-up disguised as a routine CAPTCHA check, instructing them to copy a command and paste it into the Mac Terminal application – a social engineering technique the security vendor says has surged in popularity in recent years.

Once executed, the command quietly pulled down a Bash loader that fingerprinted the machine before fetching a Go-based Mach-O payload tailored to the device’s processor architecture. The malware was built to harvest credentials from the Apple Keychain, browser password stores and cached browser cookies. To avoid detection, it wrote itself into a folder disguised as a legitimate Apple system process and stripped the file of the quarantine flag that would normally trigger a Gatekeeper security warning.

The malware’s standout feature, according to Huntress, is a function it calls DRAIN, which checks whether a detected cryptocurrency wallet holds a balance and, if so, transfers either a set percentage or the entire amount to a wallet controlled by the attacker. The code included dedicated routines for Bitcoin, Litecoin, Dogecoin, Ethereum and XRP, along with variables to calculate what a given percentage of a wallet’s contents would be worth – allowing operators to bleed a wallet dry incrementally rather than emptying it in one obvious transaction. Huntress noted this is the first time it had observed wallet-draining malware built to remove a controlled fraction of funds rather than the full balance outright.

Investigators also found the attackers used an osascript-generated dialogue box to trick the victim into re-entering their system password, granting the malware elevated privileges without raising suspicion.

Infrastructure analysis tied the loader, payload hosting and command-and-control server to IP address ranges operated by Aeza Group, a Russian bulletproof hosting provider. Aeza Group was sanctioned by the US Treasury’s Office of Foreign Assets Control in July 2025, with the UK and Australia joining a further round of sanctions against ransomware infrastructure providers in November 2025.

Huntress is urging organisations to treat ClickFix-style prompts as a red flag and to train staff never to paste unknown commands into a terminal window. The firm also recommends malicious-script mitigation browser extensions and DNS-level blocking of known-bad domains as additional layers of defence, alongside immediate isolation of any machine where a ClickFix command has been run.

The company has published indicators of compromise, including file hashes and the IP addresses involved, via its GitHub threat-intelligence repository.

You can read more here: https://www.huntress.com/blog/mac-crypto-draining-malware

ShareTweet
Previous Post

Kill switch fears now rival ransomware as a top security risk for European businesses, Proton study finds

Next Post

What Is Shadow AI And Why Is It A Growing Risk For Companies?

Recent News

Filigran Backs Security Serious Unsung Heroes Awards as New Sponsor

Filigran Backs Security Serious Unsung Heroes Awards as New Sponsor

September 18, 2026
Four AI Agent Security Risks Organisations Can’t Afford to Ignore

Four AI Agent Security Risks Organisations Can’t Afford to Ignore

September 18, 2026
New Settra Ransomware Strain Deploys MeshAgent RMM for Persistence

New Settra Ransomware Strain Deploys MeshAgent RMM for Persistence

September 17, 2026
When Everyday Habits Become an Invisible Security Risk

When Everyday Habits Become an Invisible Security Risk

September 17, 2026

Eskenzi PR banner ad

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol