"While the malware payload is capable of stealing passwords, its most interesting function is its capability to slowly deplete cryptocurrency accounts, siphoning their contents into accounts under the threat actor's control," Huntress security researcher Andrew Brandt said.
How the ClickFix chain infects macOS hosts
The attack begins with a deceptively simple instruction: paste a ClickFix command into the macOS Terminal app. That action executes a Bash profiler/loader that collects extensive system details, then fetches a Mach‑O payload tailored to the victim's CPU architecture. The loader matches payloads to the host processor and delivers a Go‑based stealer compatible with the targeted machine.
The Go stealer's DRAIN routine and targeted cryptocurrencies
Beyond classical credential theft, the malware packs a "DRAIN" routine that actively inspects cryptocurrency wallets and redirects value to attacker‑controlled addresses. Multiple versions of the DRAIN function exist for specific cryptocurrencies, including Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and Ripple's XRP. Huntress highlighted that the malware contains separate functions to determine the value of 1% of a wallet's contents, and that it can be configured to siphon a portion or the entirety of a wallet's funds.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleCredential theft, fake prompts, and exfiltration
The payload can capture browser‑stored passwords, Apple iCloud Keychain data, and cached credentials. Like other macOS stealers, it attempts privilege escalation through social engineering: victims see a fake prompt citing an "unexpected system error" and a purported attempt to restore damaged system files, and are asked to enter system credentials. Stolen data and harvested credentials are transmitted to a remote server under the control of the threat actor.
Aeza Group hosting: staging servers and C2 infrastructure
Huntress tied both the servers staging malicious payloads and the command‑and‑control (C2) systems for the campaign to infrastructure operated by Aeza Group. The source describes Aeza Group as a Russian bulletproof hosting provider that has been sanctioned by the U.S., the U.K., and Australia for facilitating bad actors. Those infrastructure links place the delivery and control points for this malware on hosts already singled out by sanctions authorities.
Related ClickFix variants and concurrent stealer campaigns
The disclosure arrives as multiple ClickFix campaigns and other stealer operations have been observed in recent weeks. Palo Alto Networks Unit 42 reported a macOS ClickFix campaign distributing MacSync and Atomic Stealer that uses look‑alike domains and a server‑side browser‑fingerprinting and hardware‑validation gate to serve lures only to visitors whose environment appears to be a genuine macOS browser, blocking crawlers and sandboxes.
Unit 42 also described a Windows ClickFix variant that abuses Program Compatibility Assistant (pcalua.exe) as a launcher. In that chain, a crafted command pasted by the victim spawns PowerShell, uses WMI to create cmd.exe, mounts a remote WebDAV share, and loads a malicious DLL through rundll32.exe; the WebDAV share is exposed over HTTPS via CDN‑fronted infrastructure at a per‑victim tokenized URL used to deliver the DLL and deploy infostealer capabilities.
Another observed ClickFix variant uses on‑the‑fly WebAssembly (wasm) module instantiation and steganography via SVG images to evade network detection. In that flow, legitimate‑but‑compromised websites run injected JavaScript that builds a wasm module exporting URLs; SVG files are downloaded and used to construct the final ClickFix URL, which is dropped onto the DOM with a script tag to display a fake verification page. The fake page presents a checkbox and then instructions to paste content into a Run window—triggering the same sort of paste‑to‑execute behavior exploited in the macOS chain.
Separately, two other stealer campaigns were described: one that delivers Lumma Stealer via files disguised as 1080p WEBRip and Blu‑ray releases of The Odyssey, and another that uses cracked software and pirated game lures hosted on SEO‑poisoned fake websites to drop Remus, a 64‑bit variant of Lumma Stealer.
What this means for macOS security teams, end users, and sanctions authorities
- macOS security teams: will need to consider detection and user‑interaction controls that address paste‑to‑Terminal flows, architecture‑aware payload staging, and monitoring for exfiltration to hosting providers tied to Aeza Group.
- End users: are the immediate targets of social‑engineering steps such as fake system error prompts and copy‑paste instructions; the campaigns show a recurring reliance on manual paste actions and fake verification pages to defeat automated sandboxing and crawler defenses.
- Sanctions authorities and infrastructure monitors: the linkage to Aeza Group reinforces the role of sanctioned bulletproof hosts in enabling multi‑platform crimeware, and underscores why observers are tracking hosting ties alongside malware capability.
Huntress calls out a particularly notable evolution: defenders are now observing malware that not only extracts credentials but also calculates portions of a wallet's value and redirects funds in configurable increments, rather than only emptying wallets outright. That functional combination—credential theft, privilege escalation via fake prompts, and a configurable crypto DRAIN—ties sophisticated delivery techniques to infrastructure already identified by sanctions regimes, leaving defenders to block both the technical chain and the human steps that activate it.




