Skip to main content
AVOID.NET

Fact-check findings

What an automated fact-checker found when it re-read ClickFix macOS Go-Based Infostealer Crypto Wallet Drainer (August 2026) against the sources the page cites. Only the most recent review is shown.

Read this first

These findings are produced by an automated reviewer, and its results vary between runs: the same page, checked three times on the same day, came back with 15%, 20% and 34% of its claims disputed, mostly because each run extracted a different number of claims. Treat what follows as leads, not rulings.

“Disputed” means the reviewer could not reconcile the claim with the evidence it cited. It does not mean the claim is false. “Unverifiable” means no reachable source settled it either way.

Nothing here changes the page on its own. A proposed correction is applied only after a human moderator approves it; until then the page reads as it did when reviewed.

disputed

3 claims

The reviewer could not reconcile the claim with the evidence it cited. This is a lead, not a ruling that the claim is false.

  1. #22[disputed][awaiting moderator]in section: C2 Infrastructure and Aeza Group Attribution
    “Australia imposed additional sanctions on Aeza-related infrastructure in a subsequent November 2025 round targeting ransomware infrastructure providers.”
    reviewerAustralia imposed additional sanctions on Aeza-related infrastructure in a November 2025 round targeting ransomware infrastructure providers.Australia's own Department of Foreign Affairs/Minister for Foreign Affairs press release identifies its November 2025 sanctions targets as Media Land LLC and ML Cloud LLC, not Aeza-related infrastructure. It was the U.S. and UK, not Australia, that expanded Aeza-linked designations in that round.
    Proposed correction (not yet applied)
    Australia's sanctions in that November 2025 round targeted the separate Media Land LLC and ML Cloud LLC bulletproof hosting network and two of its personnel, rather than Aeza-related infrastructure; the U.S. and UK expanded designations to additional Aeza successor entities and individuals in that same round.
  2. #28[disputed][awaiting moderator]in the timeline
    “Australia imposed additional sanctions on Aeza-related infrastructure in a round targeting ransomware infrastructure providers; UK had already joined the July 2025 U.S. designation of Aeza International Ltd.”
    reviewerAustralia imposed additional sanctions on Aeza-related infrastructure in a November 2025 round; UK had already joined the July 2025 designation.Same underlying defect as the sections[4] Australia finding — the timeline entry repeats the same misattribution.
    Proposed correction (not yet applied)
    Australia sanctioned the separate Media Land LLC and ML Cloud LLC bulletproof hosting network (not Aeza-related infrastructure) in a coordinated round targeting ransomware infrastructure providers; UK had already joined the July 2025 U.S. designation of Aeza International Ltd.
  3. #31[disputed][awaiting moderator]in the timeline
    “AppleInsider, The Hacker News, BleepingComputer, IT Security Guru, Infosecurity Magazine, SOC Prime, and AppleMagazine covered the findings the same day.”
    reviewerHuntress published its full technical analysis on August 6, 2026, and AppleInsider, The Hacker News, BleepingComputer, IT Security Guru, Infosecurity Magazine, SOC Prime, and AppleMagazine covered the findings the same day.At least three of the seven named outlets (The Hacker News, Infosecurity Magazine, SOC Prime) published their coverage one to four days after Huntress's report, not the same day as the timeline entry states.
    Proposed correction (not yet applied)
    AppleInsider, BleepingComputer, and IT Security Guru covered the findings the same day, while The Hacker News (August 7), Infosecurity Magazine (August 10), and SOC Prime (August 10) published their coverage in the days that followed.

unverifiable

2 claims

No source the reviewer could reach confirms or contradicts the claim.

  1. #9[unverifiable][awaiting moderator]in section: DRAIN Function and Cryptocurrency Targeting
    “Brandt noted this partial-drain capability — the ability to extract less than the wallet's full balance — was the first time Huntress had observed this design in wallet-draining macOS malware, as it allows operators to avoid immediate victim detection by bleeding funds incrementally.”
    reviewerBrandt stated this partial-drain design was the first time Huntress had observed this capability in wallet-draining macOS malware.Plausible and attributed to Brandt, but this is a claim about Huntress's internal historical observations that cannot be independently verified from outside reporting.
  2. #15[unverifiable][awaiting moderator]in section: Credential and Data Theft Capabilities
    “Huntress noted that persistence is not guaranteed in all infection instances, and that deletion of the binary is sufficient to remediate the infection without risk of spontaneous reconstitution.”
    reviewerHuntress noted persistence is not guaranteed in all infection instances, and deletion of the binary is sufficient to remediate without risk of spontaneous reconstitution.Plausible remediation guidance but could not be independently located in the source text consulted.

partially supported

3 claims

The cited evidence supports part of the claim but not all of it.

  1. #7[partially supported][awaiting moderator]in the summary
    “The malware contains a dedicated DRAIN function capable of intercepting cryptocurrency transactions across Bitcoin, Ethereum, Litecoin, Dogecoin, Monero, and XRP, and additionally harvests Apple Keychain credentials, browser passwords, and cached cookies.”
    reviewerThe summary states the DRAIN function is 'capable of intercepting cryptocurrency transactions across Bitcoin, Ethereum, Litecoin, Dogecoin, Monero, and XRP,' listing Monero on equal footing with the other five currencies.The page's own section 3 correctly notes Monero lacked a full drain routine, but the summary flattens this distinction and implies equal DRAIN capability across all six currencies, overstating the source.
  2. #20[partially supported][awaiting moderator]in section: C2 Infrastructure and Aeza Group Attribution
    “According to the Treasury press release, Aeza Group had provided bulletproof hosting infrastructure to operators of the Meduza and Lumma infostealer families, the BianLian ransomware group, and administrators of the BlackSprut darknet drug marketplace.”
    reviewerAccording to the Treasury press release, Aeza Group provided bulletproof hosting to Meduza, Lumma, BianLian, and BlackSprut.The named families are accurate as far as they go but the list silently drops RedLine, which the cited press release explicitly names alongside Meduza, Lumma and BianLian.
  3. #27[partially supported][awaiting moderator]in the timeline
    “U.S. Treasury OFAC sanctioned Aeza Group LLC and three affiliated entities (Aeza International Ltd., Aeza Logistic LLC, Cloud Solutions LLC) along with four individual executives, for providing bulletproof hosting infrastructure to ransomware and infostealer operators including Meduza, Lumma, and BianLian.”
    reviewerU.S. Treasury OFAC sanctioned Aeza Group LLC and three affiliated entities plus four executives on July 1, 2025, for hosting Meduza, Lumma, and BianLian.Core sanction date, entities and executives are correct; the malware-family list again omits RedLine, which the cited primary source names. Same defect as the sections[4] finding.

confirmed

23 claims

The cited evidence supports the claim as written.

  1. #1[confirmed][no action needed]in section: Threat Overview and Discovery
    “Huntress MDR security researcher Andrew Brandt published findings on August 6, 2026, documenting a Go-based macOS stealer discovered during a retrospective threat hunt conducted in June 2026.”
    reviewerHuntress MDR researcher Andrew Brandt published findings on August 6, 2026 documenting a Go-based macOS stealer discovered during a retrospective threat hunt.Directly confirmed by the primary Huntress blog post.
  2. #2[confirmed][no action needed]in section: Threat Overview and Discovery
    “Analysts determined the monitored endpoint had been infected approximately three months prior — placing the initial compromise around March 2026 — and that the infection had remained dormant and undetected for that entire period.”
    reviewerThe infected endpoint had been compromised approximately three months before the June 2026 threat hunt, placing initial compromise around March 2026, and the infection remained dormant/undetected that whole period.Consistent with Huntress's own reporting.
  3. #3[confirmed][no action needed]in section: Threat Overview and Discovery
    “The malware is compiled as a Mach-O executable and delivered as an architecture-specific payload (ARM64 or x86_64) depending on the victim's hardware.”
    reviewerThe malware is compiled as a Mach-O executable delivered as an architecture-specific payload (ARM64 or x86_64).Confirmed.
  4. #4[confirmed][no action needed]in section: ClickFix Delivery Mechanism
    “The technique exploits user trust in routine verification flows rather than any macOS vulnerability; there is no zero-day or remote code execution exploit involved.”
    reviewerThe ClickFix technique uses a fake CAPTCHA/error prompt to get the victim to paste a Bash command into Terminal, with no zero-day or RCE exploit involved.Standard, well-corroborated description of the ClickFix technique.
  5. #5[confirmed][no action needed]in section: ClickFix Delivery Mechanism
    “Microsoft's Security Blog noted on August 5, 2026 — one day before the Huntress publication — that a macOS ClickFix campaign had evolved to include obfuscation improvements.”
    reviewerMicrosoft's Security Blog noted on August 5, 2026 — one day before the Huntress publication — that a macOS ClickFix campaign had evolved to include obfuscation improvements.Date and content confirmed directly against the Microsoft post.
  6. #6[confirmed][no action needed]in section: DRAIN Function and Cryptocurrency Targeting
    “Huntress also identified variables associated with Monero (XMR), though the analyzed ARM64 sample did not include a fully implemented drain routine for Monero specifically, according to the AppleInsider report.”
    reviewerThe DRAIN function has dedicated wallet-handling routines for BTC, LTC, DOGE, ETH and XRP; Monero variables exist but the analyzed sample lacked a fully implemented Monero drain routine.Well corroborated and correctly nuanced by the page in this section.
  7. #8[confirmed][no action needed]in section: DRAIN Function and Cryptocurrency Targeting
    “A variable named DRAIN_PCT controls what fraction of a wallet's balance is siphoned in each operation.”
    reviewerA variable named DRAIN_PCT controls what fraction of a wallet's balance is siphoned per operation, enabling partial drains.Confirmed.
  8. #10[confirmed][no action needed]in section: DRAIN Function and Cryptocurrency Targeting
    “Importantly, analysis of attacker-controlled wallet addresses embedded in the sample showed no recorded incoming transactions at the time of the Huntress report, meaning there is no confirmed on-chain evidence of funds successfully drained from victims in this specific campaign as of the publication date.”
    reviewerAnalysis of attacker-controlled wallet addresses embedded in the sample showed no recorded incoming transactions at the time of the Huntress report.Directly confirmed.
  9. #11[confirmed][no action needed]in section: Credential and Data Theft Capabilities
    “Confirmed data exfiltration targets identified by Huntress include: Apple Keychain credentials (which may contain passwords for email, banking, VPN, and other sensitive services stored by macOS), browser-stored password databases, cached browser cookies (which can enable session hijacking independent of passwords), and cached system credentials.”
    reviewerConfirmed exfiltration targets include Apple Keychain credentials, browser-stored password databases, and cached browser cookies.Confirmed against both primary and secondary reporting.
  10. #12[confirmed][no action needed]in section: Credential and Data Theft Capabilities
    “The malware uses osascript — Apple's scripting bridge for AppleScript — to generate native-looking macOS system dialogs prompting users for their account password, enabling privilege escalation or credential capture under the guise of a legitimate system prompt.”
    reviewerThe malware uses osascript to generate native-looking macOS system dialogs prompting for the account password.Confirmed.
  11. #13[confirmed][no action needed]in section: Credential and Data Theft Capabilities
    “The payload is placed at the path $HOME/Library/Caches/com.apple.trustd/com.apple.verified, a location chosen to mimic a legitimate Apple system directory and avoid casual detection.”
    reviewerThe payload is placed at $HOME/Library/Caches/com.apple.trustd/com.apple.verified, mimicking a legitimate Apple system directory.Exact path confirmed verbatim against the Huntress blog.
  12. #14[confirmed][no action needed]in section: Credential and Data Theft Capabilities
    “Persistence is established via a LaunchAgent plist named com.apple.softwareupdated.plist.”
    reviewerPersistence is established via a LaunchAgent plist named com.apple.softwareupdated.plist.Confirmed verbatim.
  13. #16[confirmed][no action needed]in section: C2 Infrastructure and Aeza Group Attribution
    “Specific IP addresses documented in Huntress's analysis include 193.29.224.151, 77.221.152.34, and 138.124.118.69.”
    reviewerHuntress traced C2/loader/payload infrastructure to IPs 193.29.224.151, 77.221.152.34, and 138.124.118.69 within AS210644, operated by Aeza Group.IP addresses and AS attribution match the source exactly.
  14. #17[confirmed][no action needed]in section: C2 Infrastructure and Aeza Group Attribution
    “The initial loader command contacted https://profitnow[.]io/ and http://193.29.224.151/92392991a0cca55?force=1.”
    reviewerThe initial loader command contacted https://profitnow[.]io/ and http://193.29.224.151/92392991a0cca55?force=1.Confirmed verbatim, including the specific loader path and query parameter.
  15. #18[confirmed][no action needed]in section: C2 Infrastructure and Aeza Group Attribution
    “C2 communication operates over port 8133/tcp via HTTP.”
    reviewerC2 communication operates over port 8133/tcp via HTTP.Confirmed.
  16. #19[confirmed][no action needed]in section: C2 Infrastructure and Aeza Group Attribution
    “Aeza Group is a St. Petersburg, Russia-based bulletproof hosting provider that was formally sanctioned by the U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) on July 1, 2025, under the designation sb0185.”
    reviewerAeza Group was sanctioned by OFAC on July 1, 2025 under designation sb0185, along with three affiliated entities and four named executives with specified roles/ownership percentages.Fully confirmed against the primary Treasury source, including individual names, titles and ownership stakes.
  17. #21[confirmed][no action needed]in section: C2 Infrastructure and Aeza Group Attribution
    “The UK National Crime Agency joined the designation of Aeza International Ltd. on the same date; Australia imposed additional sanctions on Aeza-related infrastructure in a subsequent November 2025 round targeting ransomware infrastructure providers.”
    reviewerThe UK National Crime Agency joined the designation of Aeza International Ltd. on the same date (July 1, 2025).This clause of the sentence is confirmed; the Australia clause of the same sentence is a separate, disputed claim below.
  18. #23[confirmed][no action needed]in section: Indicators of Compromise (IOCs)
    “File hashes (SHA-256): stealer payload (ARM64 Mach-O): f0062f7e70e61493684a2f60748a475168e155bc2502163c844c42e87692abd0; Bash profiler/loader: 5bad988affc1094f12b8b8bed659ef55b20e2988eb25441e1c1b34dd03b3eb52.”
    reviewerThe file hashes documented as IOCs (ARM64 stealer payload and Bash profiler/loader SHA-256 values) match Huntress's published indicators.The two hashes given are confirmed correct; the page omits the separate x86_64 stealer hash Huntress also published (noted as a coverage gap, not a factual error).
  19. #24[confirmed][no action needed]in section: Broader ClickFix Campaign Context
    “The ClickFix technique predates this specific campaign and has been documented across Windows and macOS platforms since at least mid-2024.”
    reviewerThe ClickFix technique has been documented across Windows and macOS platforms since at least mid-2024.The hedged phrasing is defensible; some trackers date the earliest ClickFix variant to late 2023, but mid-2024 mainstream emergence is well documented.
  20. #25[confirmed][no action needed]in section: Broader ClickFix Campaign Context
    “The broader infostealer ecosystem on macOS has expanded significantly in 2024-2026, with families including AMOS (Atomic macOS Stealer), MacSync, and unnamed Go-based stealers all observed in active campaigns.”
    reviewerThe broader macOS infostealer ecosystem in 2024-2026 includes AMOS (Atomic macOS Stealer), MacSync, and unnamed Go-based stealers.Both named families (AMOS, MacSync) are independently verifiable as real, active macOS stealer families.
  21. #26[confirmed][no action needed]in section: Victim Impact and Confirmed Damage
    “The campaign's known victim count is limited to the single confirmed Huntress MDR endpoint, though the retrospective nature of the discovery — finding infections months after the fact — means the true scope of compromise is unknown.”
    reviewerThe campaign's known victim count is limited to the single confirmed Huntress MDR endpoint, though true scope of compromise is unknown given the retrospective discovery.Reasonable, appropriately hedged characterization consistent with the sourcing.
  22. #29[confirmed][no action needed]in the timeline
    “AppleInsider reported on a separate but related macOS ClickFix CAPTCHA campaign using Terminal-paste delivery already active in the wild, documenting the social engineering technique broadly.”
    reviewerAppleInsider reported on March 10, 2026 on a separate but related macOS ClickFix CAPTCHA campaign using Terminal-paste delivery already active in the wild.Date and characterization confirmed; correctly distinguished by the page as a separate, earlier campaign rather than the same malware.
  23. #30[confirmed][no action needed]in the timeline
    “Huntress analyst Andrew Brandt discovered components of the Go-based macOS stealer during a retrospective threat hunt on a monitored endpoint, identifying the March 2026 infection approximately three months after the fact.”
    reviewerHuntress analyst Andrew Brandt discovered the stealer during a retrospective threat hunt in June 2026, identifying the March 2026 infection approximately three months after the fact.Confirmed.
How this fits together. The reviewer reads the published page and its cited sources and records one finding per claim. A human moderator decides whether each proposed correction is applied; those decisions, and the score changes they cause, appear in the audit log. Earlier review runs are not shown here; only the latest reflects the page as it stands.