Skip to main content
AVOID.NET

ClickFix macOS Go-Based Infostealer Crypto Wallet Drainer (August 2026)

avoid.net/clickfix-macos-go-based-infostealer-crypto-wallet-drainer-august-2026→0/100·91% conf.
[VERIFIED]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·212VDa…yhHe

Summary

A Go-based macOS infostealer delivered via ClickFix fake-CAPTCHA social engineering was confirmed active in August 2026 after Huntress MDR analysts discovered it during a retrospective threat hunt covering an infection that occurred approximately three months earlier. The malware contains a dedicated DRAIN function capable of intercepting cryptocurrency transactions across Bitcoin, Ethereum, Litecoin, Dogecoin, Monero, and XRP, and additionally harvests Apple Keychain credentials, browser passwords, and cached cookies. All command-and-control, loader, and payload hosting infrastructure was traced by Huntress to IP address ranges operated by Aeza Group, a Russian bulletproof hosting provider sanctioned by the U.S. Treasury's OFAC on July 1, 2025.

Connected Entities

7 entities · 60 linked investigations
Organizations
Protocols
⌂ClickFix macOS Go-Based Infostealer Crypto Wallet Drainer (August 2026)
Tokens
Relationships
  • Ethereum→mentioned with→Bitcoin(60%)
  • Monero→mentioned with→Bitcoin(60%)
  • Litecoin→mentioned with→Bitcoin(70%)
  • Litecoin→mentioned with→Monero(65%)
  • ClickFix macOS Go-Based Infostealer Crypto Wallet Drainer (August 2026)→mentioned with→Bitcoin(65%)
  • ClickFix macOS Go-Based Infostealer Crypto Wallet Drainer (August 2026)→mentioned with→Dogecoin(65%)
  • ClickFix macOS Go-Based Infostealer Crypto Wallet Drainer (August 2026)→mentioned with→Litecoin(65%)
  • ClickFix macOS Go-Based Infostealer Crypto Wallet Drainer (August 2026)→mentioned with→Monero(70%)
  • ClickFix macOS Go-Based Infostealer Crypto Wallet Drainer (August 2026)→mentioned with→Ethereum(65%)
  • ClickFix macOS Go-Based Infostealer Crypto Wallet Drainer (August 2026)→mentioned with→Aeza Group(80%)
  • + 1 more
Have evidence about ClickFix macOS Go-Based Infostealer Crypto Wallet Drainer (August 2026)?

Timeline(7 events)

July 2025

U.S. Treasury OFAC sanctioned Aeza Group LLC and three affiliated entities (Aeza International Ltd., Aeza Logistic LLC, Cloud Solutions LLC) along with four individual executives, for providing bulletproof hosting infrastructure to ransomware and infostealer operators including Meduza, Lumma, and BianLian.

U.S. Department of the Treasury

November 2025

Australia imposed additional sanctions on Aeza-related infrastructure in a round targeting ransomware infrastructure providers; UK had already joined the July 2025 U.S. designation of Aeza International Ltd.

Security Affairs

March 2026

Approximate date of initial infection: A macOS endpoint monitored by Huntress MDR was compromised via a ClickFix social engineering attack, installing the Go-based infostealer. The infection remained undetected for approximately three months.

Huntress Blog

10 March 2026

AppleInsider reported on a separate but related macOS ClickFix CAPTCHA campaign using Terminal-paste delivery already active in the wild, documenting the social engineering technique broadly.

AppleInsider

June 2026

Huntress analyst Andrew Brandt discovered components of the Go-based macOS stealer during a retrospective threat hunt on a monitored endpoint, identifying the March 2026 infection approximately three months after the fact.

Huntress Blog

5 August 2026

Microsoft Security Blog published an analysis documenting that a macOS ClickFix campaign had evolved to include new obfuscation techniques, providing broader context for the threat landscape one day before the Huntress publication.

Microsoft Security Blog

6 August 2026

Huntress published full technical analysis of the Go-based macOS infostealer, documenting the DRAIN function, Aeza Group C2 infrastructure, IOCs, and remediation steps. AppleInsider, The Hacker News, BleepingComputer, IT Security Guru, Infosecurity Magazine, SOC Prime, and AppleMagazine covered the findings the same day.

Huntress Blog
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (4 events). 20 of 21 cited source URLs have an Internet Archive snapshot.

Fact-checked 2026-09-0731 claims checked3 corrections pending0 applied⛓ anchoredSee findings →

model: claude-sonnet-4-6

generated: 8/15/2026, 11:07:51 PM

last updated: 8/25/2026, 7:47:12 PM

4 views

avoid.net — verified advice for a post-truth world