Anatomy of a macOS ClickFix Crimekit that Weaponises EtherHiding
This macOS malware campaign uses social engineering via fake CAPTCHA pages to trick victims into running malicious AppleScript commands. It installs a persistent backdoor that leverages EtherHiding by storing command-and-control (C2) addresses in Polygon blockchain smart contracts, complicating detection. The malware maintains persistence through LaunchAgents and deploys multiple payloads, including the AMOS stealer targeting cryptocurrency wallets, browser credentials, and macOS Keychain data, as well as the XMRig cryptominer for ongoing revenue. The campaign employs advanced evasion techniques such as character-ID obfuscation and abuse of legitimate macOS utilities. Blockchain transaction analysis provides defenders with insights into C2 infrastructure despite the malware's memory-resident execution model.
AI Analysis
Technical Summary
This sophisticated macOS campaign exploits ClickFix social engineering to deceive victims into executing malicious AppleScript commands via fake CAPTCHA verification pages. The attack chain installs a persistent backdoor agent that uses EtherHiding, storing C2 addresses within Polygon blockchain smart contracts, which makes infrastructure detection challenging. Persistence is achieved through LaunchAgents, and the malware deploys multiple payloads including the AMOS stealer, which targets cryptocurrency wallets, browser credentials, and macOS Keychain data, alongside the XMRig cryptominer for sustained revenue generation. The operation demonstrates advanced evasion techniques such as character-ID obfuscation, blockchain-based infrastructure, and abuse of legitimate macOS utilities. Analysis of blockchain transactions reveals the complete C2 rotation history and funding trails, offering defenders infrastructure-level pivots despite the campaign's memory-resident execution model.
Potential Impact
The campaign compromises macOS systems by installing a persistent backdoor that steals sensitive information including cryptocurrency wallets, browser credentials, and Keychain data. It also runs a cryptominer (XMRig) that consumes system resources for illicit revenue generation. The use of blockchain-based C2 infrastructure complicates detection and takedown efforts, increasing the difficulty of defensive measures. The malware's persistence and evasion techniques increase the likelihood of prolonged unauthorized access and data exfiltration.
Mitigation Recommendations
No official patch or vendor advisory is available for this malware campaign. Defenders should focus on user education to prevent social engineering attacks, monitor for suspicious AppleScript execution, and investigate persistence mechanisms such as LaunchAgents on macOS systems. Blockchain analysis can provide indicators of compromise related to C2 infrastructure. Since the malware abuses legitimate macOS utilities, behavioral detection and endpoint monitoring are recommended. Patch status is not yet confirmed — check vendor advisories for any updates.
Indicators of Compromise
- domain: citcix6.xyz
- domain: sj98xe4.xyz
- domain: hf98x4d.site
- domain: xuiaxwx.com
- domain: gesck4m.pro
- domain: apdhlhs3.xyz
- domain: okekjaiw.click
- domain: 8jdjpwka.baby
- domain: fbuytf67.click
- domain: 67sixcebeh.surf
- url: https://67sixcebeh.surf/upload.php
- url: https://67sixcebeh.surf/xmr
- url: https://67sixcebeh.surf/xmr
- hash: 9a6b91a3cc2867d4d493823f425f1397afac0f52e17acae937560c3f4d73080d
- hash: e9d3dd808fa4218abdcb2a0a38a52d2337662b65a712663f35b8374476e3da65
- hash: a46d6adeb5c8e9ab5883ed8005b6ed684e7181148f5fdec7656ae6e51ca6e676
- hash: 4542d94e24b6829e262b1c4af8467e11e40f078ce135d0b110054db4b9577cf0
- hash: d0ee324b6390e9d61f9851cd1fa5f3bde4ce05821cd5b4f67ad665dbffe54ad7
- hash: f3fb674441b05fab014212ece2528c92a36df6d45b88951e65ed72606fff0c80
- hash: 872172a61e194ba96af2219b446bdb1cf318509c08ee66489aab20c1c59acf3d
- hash: 427e8b573407f6029923cdb4686b5f77
- hash: 903c7483ffa15cc14181a2dec5d8a9ddf703cddde3aa87e596d948342c8a75dc
- url: http://hf98x4d.site/upload.php
- url: https://hf98x4d.site/upload.php
- domain: citcix6.xyz67sixcebeh.surf
Anatomy of a macOS ClickFix Crimekit that Weaponises EtherHiding
Description
This macOS malware campaign uses social engineering via fake CAPTCHA pages to trick victims into running malicious AppleScript commands. It installs a persistent backdoor that leverages EtherHiding by storing command-and-control (C2) addresses in Polygon blockchain smart contracts, complicating detection. The malware maintains persistence through LaunchAgents and deploys multiple payloads, including the AMOS stealer targeting cryptocurrency wallets, browser credentials, and macOS Keychain data, as well as the XMRig cryptominer for ongoing revenue. The campaign employs advanced evasion techniques such as character-ID obfuscation and abuse of legitimate macOS utilities. Blockchain transaction analysis provides defenders with insights into C2 infrastructure despite the malware's memory-resident execution model.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This sophisticated macOS campaign exploits ClickFix social engineering to deceive victims into executing malicious AppleScript commands via fake CAPTCHA verification pages. The attack chain installs a persistent backdoor agent that uses EtherHiding, storing C2 addresses within Polygon blockchain smart contracts, which makes infrastructure detection challenging. Persistence is achieved through LaunchAgents, and the malware deploys multiple payloads including the AMOS stealer, which targets cryptocurrency wallets, browser credentials, and macOS Keychain data, alongside the XMRig cryptominer for sustained revenue generation. The operation demonstrates advanced evasion techniques such as character-ID obfuscation, blockchain-based infrastructure, and abuse of legitimate macOS utilities. Analysis of blockchain transactions reveals the complete C2 rotation history and funding trails, offering defenders infrastructure-level pivots despite the campaign's memory-resident execution model.
Potential Impact
The campaign compromises macOS systems by installing a persistent backdoor that steals sensitive information including cryptocurrency wallets, browser credentials, and Keychain data. It also runs a cryptominer (XMRig) that consumes system resources for illicit revenue generation. The use of blockchain-based C2 infrastructure complicates detection and takedown efforts, increasing the difficulty of defensive measures. The malware's persistence and evasion techniques increase the likelihood of prolonged unauthorized access and data exfiltration.
Defensive Guidance
No official patch or vendor advisory is available for this malware campaign. Defenders should focus on user education to prevent social engineering attacks, monitor for suspicious AppleScript execution, and investigate persistence mechanisms such as LaunchAgents on macOS systems. Blockchain analysis can provide indicators of compromise related to C2 infrastructure. Since the malware abuses legitimate macOS utilities, behavioral detection and endpoint monitoring are recommended. Patch status is not yet confirmed — check vendor advisories for any updates.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://notes.netbytesec.com/2026/08/anatomy-of-macos-clickfix-crimekit-that.html"]
- Adversary
- null
- Pulse Id
- 6a8c3403077781b7036ee79a
- Threat Score
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domaincitcix6.xyz | — | |
domainsj98xe4.xyz | — | |
domainhf98x4d.site | — | |
domainxuiaxwx.com | — | |
domaingesck4m.pro | — | |
domainapdhlhs3.xyz | — | |
domainokekjaiw.click | — | |
domain8jdjpwka.baby | — | |
domainfbuytf67.click | — | |
domain67sixcebeh.surf | — | |
domaincitcix6.xyz67sixcebeh.surf | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://67sixcebeh.surf/upload.php | — | |
urlhttps://67sixcebeh.surf/xmr | — | |
urlhttps://67sixcebeh.surf/xmr | — | |
urlhttp://hf98x4d.site/upload.php | — | |
urlhttps://hf98x4d.site/upload.php | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash9a6b91a3cc2867d4d493823f425f1397afac0f52e17acae937560c3f4d73080d | — | |
hashe9d3dd808fa4218abdcb2a0a38a52d2337662b65a712663f35b8374476e3da65 | — | |
hasha46d6adeb5c8e9ab5883ed8005b6ed684e7181148f5fdec7656ae6e51ca6e676 | — | |
hash4542d94e24b6829e262b1c4af8467e11e40f078ce135d0b110054db4b9577cf0 | — | |
hashd0ee324b6390e9d61f9851cd1fa5f3bde4ce05821cd5b4f67ad665dbffe54ad7 | — | |
hashf3fb674441b05fab014212ece2528c92a36df6d45b88951e65ed72606fff0c80 | — | |
hash872172a61e194ba96af2219b446bdb1cf318509c08ee66489aab20c1c59acf3d | — | |
hash427e8b573407f6029923cdb4686b5f77 | — | |
hash903c7483ffa15cc14181a2dec5d8a9ddf703cddde3aa87e596d948342c8a75dc | — |
Threat ID: 6a8c5033acd9273b49a21bc6
Added to database: 08/24/2026, 14:07:47 UTC
Last enriched: 08/24/2026, 14:23:59 UTC
Last updated: 08/24/2026, 15:32:52 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.