Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Anatomy of a macOS ClickFix Crimekit that Weaponises EtherHiding

0
Medium
Published: 08/24/2026 (08/24/2026, 12:07:31 UTC)
Source: AlienVault OTX General

Description

This macOS malware campaign uses social engineering via fake CAPTCHA pages to trick victims into running malicious AppleScript commands. It installs a persistent backdoor that leverages EtherHiding by storing command-and-control (C2) addresses in Polygon blockchain smart contracts, complicating detection. The malware maintains persistence through LaunchAgents and deploys multiple payloads, including the AMOS stealer targeting cryptocurrency wallets, browser credentials, and macOS Keychain data, as well as the XMRig cryptominer for ongoing revenue. The campaign employs advanced evasion techniques such as character-ID obfuscation and abuse of legitimate macOS utilities. Blockchain transaction analysis provides defenders with insights into C2 infrastructure despite the malware's memory-resident execution model.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/24/2026, 14:23:59 UTC

Technical Analysis

This sophisticated macOS campaign exploits ClickFix social engineering to deceive victims into executing malicious AppleScript commands via fake CAPTCHA verification pages. The attack chain installs a persistent backdoor agent that uses EtherHiding, storing C2 addresses within Polygon blockchain smart contracts, which makes infrastructure detection challenging. Persistence is achieved through LaunchAgents, and the malware deploys multiple payloads including the AMOS stealer, which targets cryptocurrency wallets, browser credentials, and macOS Keychain data, alongside the XMRig cryptominer for sustained revenue generation. The operation demonstrates advanced evasion techniques such as character-ID obfuscation, blockchain-based infrastructure, and abuse of legitimate macOS utilities. Analysis of blockchain transactions reveals the complete C2 rotation history and funding trails, offering defenders infrastructure-level pivots despite the campaign's memory-resident execution model.

Potential Impact

The campaign compromises macOS systems by installing a persistent backdoor that steals sensitive information including cryptocurrency wallets, browser credentials, and Keychain data. It also runs a cryptominer (XMRig) that consumes system resources for illicit revenue generation. The use of blockchain-based C2 infrastructure complicates detection and takedown efforts, increasing the difficulty of defensive measures. The malware's persistence and evasion techniques increase the likelihood of prolonged unauthorized access and data exfiltration.

Defensive Guidance

No official patch or vendor advisory is available for this malware campaign. Defenders should focus on user education to prevent social engineering attacks, monitor for suspicious AppleScript execution, and investigate persistence mechanisms such as LaunchAgents on macOS systems. Blockchain analysis can provide indicators of compromise related to C2 infrastructure. Since the malware abuses legitimate macOS utilities, behavioral detection and endpoint monitoring are recommended. Patch status is not yet confirmed — check vendor advisories for any updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://notes.netbytesec.com/2026/08/anatomy-of-macos-clickfix-crimekit-that.html"]
Adversary
null
Pulse Id
6a8c3403077781b7036ee79a
Threat Score
null

Indicators of Compromise

Domain

ValueDescriptionCopy
domaincitcix6.xyz
domainsj98xe4.xyz
domainhf98x4d.site
domainxuiaxwx.com
domaingesck4m.pro
domainapdhlhs3.xyz
domainokekjaiw.click
domain8jdjpwka.baby
domainfbuytf67.click
domain67sixcebeh.surf
domaincitcix6.xyz67sixcebeh.surf

Url

ValueDescriptionCopy
urlhttps://67sixcebeh.surf/upload.php
urlhttps://67sixcebeh.surf/xmr
urlhttps://67sixcebeh.surf/xmr
urlhttp://hf98x4d.site/upload.php
urlhttps://hf98x4d.site/upload.php

Hash

ValueDescriptionCopy
hash9a6b91a3cc2867d4d493823f425f1397afac0f52e17acae937560c3f4d73080d
hashe9d3dd808fa4218abdcb2a0a38a52d2337662b65a712663f35b8374476e3da65
hasha46d6adeb5c8e9ab5883ed8005b6ed684e7181148f5fdec7656ae6e51ca6e676
hash4542d94e24b6829e262b1c4af8467e11e40f078ce135d0b110054db4b9577cf0
hashd0ee324b6390e9d61f9851cd1fa5f3bde4ce05821cd5b4f67ad665dbffe54ad7
hashf3fb674441b05fab014212ece2528c92a36df6d45b88951e65ed72606fff0c80
hash872172a61e194ba96af2219b446bdb1cf318509c08ee66489aab20c1c59acf3d
hash427e8b573407f6029923cdb4686b5f77
hash903c7483ffa15cc14181a2dec5d8a9ddf703cddde3aa87e596d948342c8a75dc

Threat ID: 6a8c5033acd9273b49a21bc6

Added to database: 08/24/2026, 14:07:47 UTC

Last enriched: 08/24/2026, 14:23:59 UTC

Last updated: 08/24/2026, 15:32:52 UTC

Views: 5

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses