ClickFix macOS Go-Based Infostealer Crypto Wallet Drainer (August 2026)
Summary
A Go-based macOS infostealer delivered via ClickFix fake-CAPTCHA social engineering was confirmed active in August 2026 after Huntress MDR analysts discovered it during a retrospective threat hunt covering an infection that occurred approximately three months earlier. The malware contains a dedicated DRAIN function capable of intercepting cryptocurrency transactions across Bitcoin, Ethereum, Litecoin, Dogecoin, Monero, and XRP, and additionally harvests Apple Keychain credentials, browser passwords, and cached cookies. All command-and-control, loader, and payload hosting infrastructure was traced by Huntress to IP address ranges operated by Aeza Group, a Russian bulletproof hosting provider sanctioned by the U.S. Treasury's OFAC on July 1, 2025.
Connected Entities
1 entities · 10 linked investigationsTimeline(7 events)
2025-07-01
U.S. Treasury OFAC sanctioned Aeza Group LLC and three affiliated entities (Aeza International Ltd., Aeza Logistic LLC, Cloud Solutions LLC) along with four individual executives, for providing bulletproof hosting infrastructure to ransomware and infostealer operators including Meduza, Lumma, and BianLian.
U.S. Department of the Treasury2025-11-01
Australia imposed additional sanctions on Aeza-related infrastructure in a round targeting ransomware infrastructure providers; UK had already joined the July 2025 U.S. designation of Aeza International Ltd.
Security Affairs2026-03-01
Approximate date of initial infection: A macOS endpoint monitored by Huntress MDR was compromised via a ClickFix social engineering attack, installing the Go-based infostealer. The infection remained undetected for approximately three months.
Huntress Blog2026-03-10
AppleInsider reported on a separate but related macOS ClickFix CAPTCHA campaign using Terminal-paste delivery already active in the wild, documenting the social engineering technique broadly.
AppleInsider2026-06-01
Huntress analyst Andrew Brandt discovered components of the Go-based macOS stealer during a retrospective threat hunt on a monitored endpoint, identifying the March 2026 infection approximately three months after the fact.
Huntress Blog2026-08-05
Microsoft Security Blog published an analysis documenting that a macOS ClickFix campaign had evolved to include new obfuscation techniques, providing broader context for the threat landscape one day before the Huntress publication.
Microsoft Security Blog2026-08-06
Huntress published full technical analysis of the Go-based macOS infostealer, documenting the DRAIN function, Aeza Group C2 infrastructure, IOCs, and remediation steps. AppleInsider, The Hacker News, BleepingComputer, IT Security Guru, Infosecurity Magazine, SOC Prime, and AppleMagazine covered the findings the same day.
Huntress BlogDecision Log
- #1publish⛓ pending8/15/2026, 11:08:00 PMhash: DXBZL6E6TceBZXuzNA1EkJrcEDChS7XkWAAiL8K5Xj74
20 of 21 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 8/15/2026, 11:07:51 PM
last updated: 8/16/2026, 7:16:34 AM
avoid.net — verified advice for a post-truth world