ClickFix macOS Go-Based Infostealer Crypto Wallet Drainer (August 2026)
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·212VDa…yhHeSummary
A Go-based macOS infostealer delivered via ClickFix fake-CAPTCHA social engineering was confirmed active in August 2026 after Huntress MDR analysts discovered it during a retrospective threat hunt covering an infection that occurred approximately three months earlier. The malware contains a dedicated DRAIN function capable of intercepting cryptocurrency transactions across Bitcoin, Ethereum, Litecoin, Dogecoin, Monero, and XRP, and additionally harvests Apple Keychain credentials, browser passwords, and cached cookies. All command-and-control, loader, and payload hosting infrastructure was traced by Huntress to IP address ranges operated by Aeza Group, a Russian bulletproof hosting provider sanctioned by the U.S. Treasury's OFAC on July 1, 2025.
Connected Entities
7 entities · 60 linked investigations- Ethereum→mentioned with→Bitcoin(60%)
- Monero→mentioned with→Bitcoin(60%)
- Litecoin→mentioned with→Bitcoin(70%)
- Litecoin→mentioned with→Monero(65%)
- ClickFix macOS Go-Based Infostealer Crypto Wallet Drainer (August 2026)→mentioned with→Bitcoin(65%)
- ClickFix macOS Go-Based Infostealer Crypto Wallet Drainer (August 2026)→mentioned with→Dogecoin(65%)
- ClickFix macOS Go-Based Infostealer Crypto Wallet Drainer (August 2026)→mentioned with→Litecoin(65%)
- ClickFix macOS Go-Based Infostealer Crypto Wallet Drainer (August 2026)→mentioned with→Monero(70%)
- ClickFix macOS Go-Based Infostealer Crypto Wallet Drainer (August 2026)→mentioned with→Ethereum(65%)
- ClickFix macOS Go-Based Infostealer Crypto Wallet Drainer (August 2026)→mentioned with→Aeza Group(80%)
- + 1 more
Timeline(7 events)
July 2025
U.S. Treasury OFAC sanctioned Aeza Group LLC and three affiliated entities (Aeza International Ltd., Aeza Logistic LLC, Cloud Solutions LLC) along with four individual executives, for providing bulletproof hosting infrastructure to ransomware and infostealer operators including Meduza, Lumma, and BianLian.
U.S. Department of the TreasuryNovember 2025
Australia imposed additional sanctions on Aeza-related infrastructure in a round targeting ransomware infrastructure providers; UK had already joined the July 2025 U.S. designation of Aeza International Ltd.
Security AffairsMarch 2026
Approximate date of initial infection: A macOS endpoint monitored by Huntress MDR was compromised via a ClickFix social engineering attack, installing the Go-based infostealer. The infection remained undetected for approximately three months.
Huntress Blog10 March 2026
AppleInsider reported on a separate but related macOS ClickFix CAPTCHA campaign using Terminal-paste delivery already active in the wild, documenting the social engineering technique broadly.
AppleInsiderJune 2026
Huntress analyst Andrew Brandt discovered components of the Go-based macOS stealer during a retrospective threat hunt on a monitored endpoint, identifying the March 2026 infection approximately three months after the fact.
Huntress Blog5 August 2026
Microsoft Security Blog published an analysis documenting that a macOS ClickFix campaign had evolved to include new obfuscation techniques, providing broader context for the threat landscape one day before the Huntress publication.
Microsoft Security Blog6 August 2026
Huntress published full technical analysis of the Go-based macOS infostealer, documenting the DRAIN function, Aeza Group C2 infrastructure, IOCs, and remediation steps. AppleInsider, The Hacker News, BleepingComputer, IT Security Guru, Infosecurity Magazine, SOC Prime, and AppleMagazine covered the findings the same day.
Huntress BlogDecision Log
- hash: Eoqo1yDZFrMFVXq8R5HwcieNawTKbApQ6ecZoawjUWpT
- hash: 4RZQJbKoQFJh7HajcS8WUfdKxfoJayA8aetxkfbWRWhA
- hash: H5rqGuuB5zVLPPqJ5dGMC74Db6BBZMvca61g6UTkH5nt
- hash: DXBZL6E6TceBZXuzNA1EkJrcEDChS7XkWAAiL8K5Xj74
This investigation is cryptographically anchored to the Solana blockchain (4 events). 20 of 21 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 8/15/2026, 11:07:51 PM
last updated: 8/25/2026, 7:47:12 PM
4 viewsavoid.net — verified advice for a post-truth world