Anatomy of a macOS ClickFix Crimekit that Weaponises EtherHiding
Description
This macOS malware campaign uses social engineering via fake CAPTCHA pages to trick users into running malicious AppleScript commands. It deploys a persistent backdoor that leverages EtherHiding by storing command-and-control (C2) addresses in Polygon blockchain smart contracts, complicating detection. The malware maintains persistence through LaunchAgents and delivers multiple payloads including the AMOS stealer, which targets cryptocurrency wallets, browser credentials, and macOS Keychain data, as well as the XMRig cryptominer for ongoing revenue. The campaign employs advanced evasion techniques such as character-ID obfuscation and abuse of legitimate macOS utilities. Blockchain transaction analysis reveals the full history of C2 infrastructure rotation and funding, aiding defenders despite the malware's memory-resident nature.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
A sophisticated macOS malware campaign exploits social engineering via ClickFix fake CAPTCHA verification pages to execute malicious AppleScript commands. The attack chain installs a persistent backdoor agent that uses EtherHiding by embedding C2 addresses within Polygon blockchain smart contracts, making infrastructure detection difficult. Persistence is achieved through LaunchAgents. Payloads include the AMOS stealer, which exfiltrates cryptocurrency wallets, browser credentials, and macOS Keychain data, and the XMRig cryptominer for sustained illicit mining. The operation features advanced evasion techniques such as character-ID obfuscation and misuse of legitimate macOS utilities. Analysis of blockchain transactions provides defenders with insights into C2 rotation and funding despite the malware's memory-resident execution model.
Potential Impact
The malware compromises sensitive user data including cryptocurrency wallets, browser credentials, and macOS Keychain secrets. It also enables unauthorized cryptocurrency mining, potentially degrading system performance and increasing power consumption. The use of blockchain-based C2 infrastructure complicates detection and takedown efforts, increasing the persistence and stealth of the campaign.
Defensive Guidance
No official patch or remediation is indicated. Defenders should focus on user awareness to prevent social engineering attacks involving fake CAPTCHA pages and malicious AppleScript execution. Monitoring for suspicious LaunchAgents and unusual AppleScript activity on macOS systems may help detect infections. Analysis of blockchain transactions related to the campaign can provide intelligence for infrastructure disruption. Since this is a malware campaign rather than a software vulnerability, standard patching does not apply.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://notes.netbytesec.com/2026/08/anatomy-of-macos-clickfix-crimekit-that.html"]
- Pulse Id
- 6a8c3403077781b7036ee79a
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domaincitcix6.xyz | — | |
domainsj98xe4.xyz | — | |
domainhf98x4d.site | — | |
domainxuiaxwx.com | — | |
domaingesck4m.pro | — | |
domainapdhlhs3.xyz | — | |
domainokekjaiw.click | — | |
domain8jdjpwka.baby | — | |
domainfbuytf67.click | — | |
domain67sixcebeh.surf | — | |
domaincitcix6.xyz67sixcebeh.surf | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://67sixcebeh.surf/upload.php | — | |
urlhttps://67sixcebeh.surf/xmr | — | |
urlhttps://67sixcebeh.surf/xmr | — | |
urlhttp://hf98x4d.site/upload.php | — | |
urlhttps://hf98x4d.site/upload.php | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash9a6b91a3cc2867d4d493823f425f1397afac0f52e17acae937560c3f4d73080d | — | |
hashe9d3dd808fa4218abdcb2a0a38a52d2337662b65a712663f35b8374476e3da65 | — | |
hasha46d6adeb5c8e9ab5883ed8005b6ed684e7181148f5fdec7656ae6e51ca6e676 | — | |
hash4542d94e24b6829e262b1c4af8467e11e40f078ce135d0b110054db4b9577cf0 | — | |
hashd0ee324b6390e9d61f9851cd1fa5f3bde4ce05821cd5b4f67ad665dbffe54ad7 | — | |
hashf3fb674441b05fab014212ece2528c92a36df6d45b88951e65ed72606fff0c80 | — | |
hash872172a61e194ba96af2219b446bdb1cf318509c08ee66489aab20c1c59acf3d | — | |
hash427e8b573407f6029923cdb4686b5f77 | — | |
hash903c7483ffa15cc14181a2dec5d8a9ddf703cddde3aa87e596d948342c8a75dc | — |
Threat ID: 6a8c5033acd9273b49a21bc6
Added to database: 08/24/2026, 14:07:47 UTC
Last enriched: 09/10/2026, 21:33:03 UTC
Last updated: 10/04/2026, 07:23:23 UTC
Views: 144
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.