Skip to main content

Anatomy of a macOS ClickFix Crimekit that Weaponises EtherHiding

0
Medium
Published: 08/24/2026 (08/24/2026, 12:07:31 UTC)
Source: AlienVault OTX General

Description

This macOS malware campaign uses social engineering via fake CAPTCHA pages to trick users into running malicious AppleScript commands. It deploys a persistent backdoor that leverages EtherHiding by storing command-and-control (C2) addresses in Polygon blockchain smart contracts, complicating detection. The malware maintains persistence through LaunchAgents and delivers multiple payloads including the AMOS stealer, which targets cryptocurrency wallets, browser credentials, and macOS Keychain data, as well as the XMRig cryptominer for ongoing revenue. The campaign employs advanced evasion techniques such as character-ID obfuscation and abuse of legitimate macOS utilities. Blockchain transaction analysis reveals the full history of C2 infrastructure rotation and funding, aiding defenders despite the malware's memory-resident nature.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/10/2026, 21:33:03 UTC

Technical Analysis

A sophisticated macOS malware campaign exploits social engineering via ClickFix fake CAPTCHA verification pages to execute malicious AppleScript commands. The attack chain installs a persistent backdoor agent that uses EtherHiding by embedding C2 addresses within Polygon blockchain smart contracts, making infrastructure detection difficult. Persistence is achieved through LaunchAgents. Payloads include the AMOS stealer, which exfiltrates cryptocurrency wallets, browser credentials, and macOS Keychain data, and the XMRig cryptominer for sustained illicit mining. The operation features advanced evasion techniques such as character-ID obfuscation and misuse of legitimate macOS utilities. Analysis of blockchain transactions provides defenders with insights into C2 rotation and funding despite the malware's memory-resident execution model.

Potential Impact

The malware compromises sensitive user data including cryptocurrency wallets, browser credentials, and macOS Keychain secrets. It also enables unauthorized cryptocurrency mining, potentially degrading system performance and increasing power consumption. The use of blockchain-based C2 infrastructure complicates detection and takedown efforts, increasing the persistence and stealth of the campaign.

Defensive Guidance

No official patch or remediation is indicated. Defenders should focus on user awareness to prevent social engineering attacks involving fake CAPTCHA pages and malicious AppleScript execution. Monitoring for suspicious LaunchAgents and unusual AppleScript activity on macOS systems may help detect infections. Analysis of blockchain transactions related to the campaign can provide intelligence for infrastructure disruption. Since this is a malware campaign rather than a software vulnerability, standard patching does not apply.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://notes.netbytesec.com/2026/08/anatomy-of-macos-clickfix-crimekit-that.html"]
Pulse Id
6a8c3403077781b7036ee79a

Indicators of Compromise

Domain

ValueDescriptionCopy
domaincitcix6.xyz
—
domainsj98xe4.xyz
—
domainhf98x4d.site
—
domainxuiaxwx.com
—
domaingesck4m.pro
—
domainapdhlhs3.xyz
—
domainokekjaiw.click
—
domain8jdjpwka.baby
—
domainfbuytf67.click
—
domain67sixcebeh.surf
—
domaincitcix6.xyz67sixcebeh.surf
—

Url

ValueDescriptionCopy
urlhttps://67sixcebeh.surf/upload.php
—
urlhttps://67sixcebeh.surf/xmr
—
urlhttps://67sixcebeh.surf/xmr
—
urlhttp://hf98x4d.site/upload.php
—
urlhttps://hf98x4d.site/upload.php
—

Hash

ValueDescriptionCopy
hash9a6b91a3cc2867d4d493823f425f1397afac0f52e17acae937560c3f4d73080d
—
hashe9d3dd808fa4218abdcb2a0a38a52d2337662b65a712663f35b8374476e3da65
—
hasha46d6adeb5c8e9ab5883ed8005b6ed684e7181148f5fdec7656ae6e51ca6e676
—
hash4542d94e24b6829e262b1c4af8467e11e40f078ce135d0b110054db4b9577cf0
—
hashd0ee324b6390e9d61f9851cd1fa5f3bde4ce05821cd5b4f67ad665dbffe54ad7
—
hashf3fb674441b05fab014212ece2528c92a36df6d45b88951e65ed72606fff0c80
—
hash872172a61e194ba96af2219b446bdb1cf318509c08ee66489aab20c1c59acf3d
—
hash427e8b573407f6029923cdb4686b5f77
—
hash903c7483ffa15cc14181a2dec5d8a9ddf703cddde3aa87e596d948342c8a75dc
—

Threat ID: 6a8c5033acd9273b49a21bc6

Added to database: 08/24/2026, 14:07:47 UTC

Last enriched: 09/10/2026, 21:33:03 UTC

Last updated: 10/04/2026, 07:23:23 UTC

Views: 144

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses