HeadlinesBriefing favicon HeadlinesBriefing.com

Mac Malware Steals Crypto Wallet Funds

AppleInsider •
×

Researchers have identified new Mac malware capable of stealing credentials and draining cryptocurrency wallets. The Go-based malware is delivered via a "ClickFix" attack, tricking users into pasting a malicious command into Terminal.

Once executed, the malware profiles the Mac, downloads a payload for Apple Silicon or Intel, and then attempts to cover its tracks. Security analysts at Huntress discovered the infection during a retrospective threat hunt, with the compromise occurring approximately three months prior. The malware searches for browser password databases, Apple Keychain data, and other credentials. A notable feature is its "DRAIN" function, which can transfer a selected percentage of a cryptocurrency wallet's balance, targeting Bitcoin, Litecoin, Dogecoin, Ethereum, and XRP.

While the malware disguises itself as legitimate Apple software and establishes persistence, it crucially relies on user interaction to run the initial command. Apple's macOS 14 update includes a security feature warning users before pasting commands from websites, but this can be overridden. Huntress found the malware's infrastructure linked to Aeza Group, a hosting provider sanctioned by the US and UK for supporting cybercrime operations. Although the draining function was identified, Huntress found no evidence of its successful use in the analyzed samples.