None
EN
ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets
['The Hacker News', 'Ravie Lakshmanan', 'Aug']
The Hacker News
ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials.
The macOS-focused infection chain is designed to deliver a shell script that profiles the host and then fetches a macOS malware payload that's compatible with the computer's CPU architecture.
"The malware contained separate functions to determine just how much 1% of the wallet's contents is worth, depending on which cryptocurrency the malware targets."
A ClickFix variant that abuses Program Compatibility Assistant ("pcalua.exe"), a legitimate Windows binary, as a launcher to bypass parent-process heuristics.
A ClickFix campaign that uses on-the-fly WebAssembly (wasm) module instantiation and steganography through SVG images to evade network-level detection.