ClickFix Social Engineering Campaigns Target macOS Users to Drain Crypto Wallets
Attackers are leveraging fake CAPTCHAs to trick Mac users into manually executing malicious code that harvests passwords and cryptocurrency assets.
Threat actors are deploying "ClickFix" social engineering tactics to deliver a variety of macOS infostealers, including MacSync and a specialized AppleScript-based stealer. These campaigns mark a significant shift in targeting, moving away from passive malware downloads toward active, user-driven execution to bypass system security.
The attack begins when victims encounter a fake CAPTCHA or a fraudulent AI tool installer. These pages prompt users to resolve a technical issue by copying a "verification code" and pasting it into their Terminal or Spotlight search bar. In reality, this code is a malicious curl command that, once executed, installs malware designed to harvest system passwords, browser cookies, and cryptocurrency wallet data. To obtain system passwords, the malware employs a fake system lock dialog to deceive the user into providing credentials.
The Mechanics of the Theft
The AppleScript-based variant of the malware is specifically engineered to target high-value financial assets. The stealer targets 16 standalone desktop cryptocurrency wallet applications, including Exodus, Atomic, and Ledger Live. Beyond standalone apps, the malware also collects data from browser extensions, targeting dozens of blockchain-specific wallets such as MetaMask and Phantom.
Additionally, suspected Russian threat actors have been linked to the use of ClickFix tactics to distribute the Atomic macOS Stealer (AMOS), further diversifying the types of malware being pushed through this vector.
Why This Shift Matters
This evolution in macOS targeting is particularly dangerous because it leverages the inherent trust users place in system dialogs and the power of AppleScript to operate within the OS. By tricking the user into manually executing the code, attackers can often circumvent traditional security boundaries that would normally block an unsigned binary from running.
Because the malware steals session cookies and targets both browser extensions and standalone apps, attackers can potentially bypass two-factor authentication (2FA) to directly drain cryptocurrency funds. This makes the campaign a high-impact threat for developers and finance professionals who frequently manage digital assets.
The Broader Threat Landscape
ClickFix was previously more common on Windows systems, but its pivot to macOS demonstrates the adaptability of social engineering. This campaign serves as a reminder that social engineering remains a primary threat to both Windows and macOS users.
Security professionals are now monitoring for further iterations of these campaigns, as the success of the "manual execution" model suggests that attackers will continue to seek ways to turn users into the primary delivery mechanism for malware.