Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Mac Malware Drains Crypto Wallets Via Fake CAPTCHA Scam

0
Medium
Published: 08/06/2026 (08/06/2026, 17:35:59 UTC)
Source: AlienVault OTX General

Description

A sophisticated macOS malware campaign leverages ClickFix social engineering to infect victims. The attack begins with a fake CAPTCHA prompt delivered via email links, tricking users into executing malicious commands in Terminal. This downloads a profiling script that collects system information and deploys architecture-specific Go-based Mach-O payloads. The stealer targets browser passwords, Apple Keychain credentials, and cryptocurrency wallets. Its most notable feature is a DRAIN function that gradually siphons cryptocurrency from victims' wallets by redirecting portions to attacker-controlled accounts. The malware supports Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and XRP. Infrastructure analysis reveals hosting through Aeza Group, a sanctioned Russian bulletproof hosting provider. The malware achieves persistence through macOS Background Task Management and uses various evasion techniques including Gatekeeper bypass and credential harvesting via fake system prompts.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/07/2026, 10:29:16 UTC

Technical Analysis

This sophisticated macOS malware campaign begins with social engineering via a fake CAPTCHA prompt sent through email links, tricking users into running commands in Terminal. The commands download a profiling script that collects system information and deploys architecture-specific Go-based Mach-O payloads. The malware steals browser passwords, Apple Keychain credentials, and cryptocurrency wallets. Its notable feature is a DRAIN function that gradually siphons cryptocurrency from victims’ wallets by redirecting portions to attacker-controlled accounts. Supported cryptocurrencies include Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and XRP. The malware maintains persistence through macOS Background Task Management and uses evasion techniques including Gatekeeper bypass and fake system prompts to harvest credentials. The hosting infrastructure is linked to Aeza Group, a known sanctioned Russian bulletproof hosting provider.

Potential Impact

The malware compromises macOS systems by stealing sensitive credentials including browser passwords and Apple Keychain data, as well as cryptocurrency wallet information. It enables attackers to gradually siphon cryptocurrency from victims’ wallets, potentially causing financial losses across multiple cryptocurrency types. The malware’s persistence and evasion techniques increase the difficulty of detection and removal, prolonging exposure and impact.

Defensive Guidance

No official patch or remediation is indicated. Mitigation should focus on user education to avoid executing commands from untrusted sources, especially those prompted by suspicious CAPTCHA-like social engineering. Monitoring for unusual background tasks and suspicious network connections to known malicious infrastructure (e.g., Aeza Group-hosted IPs and domains) may help detect infection. Use of endpoint protection solutions capable of detecting Mach-O payloads and credential-stealing behaviors is recommended. Since no vendor advisory or patch is available, users should remain vigilant and apply best practices for macOS security.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.huntress.com/blog/mac-crypto-draining-malware"]
Adversary
null
Pulse Id
6a74c5ff523b6fcb70f5711d
Threat Score
null

Indicators of Compromise

Hash

ValueDescriptionCopy
hash39854a5f9c557b8e639bdb40f1866f4b
hash504eea132c86ad37297dea78aa0e1143414d6300
hash5bad988affc1094f12b8b8bed659ef55b20e2988eb25441e1c1b34dd03b3eb52
hash619a99ba4ee9d7f33db8045c7e03c4265424977993fe8a53b0f45157c5abd3e5
hashb43a909a01e954d6549558f2f7e9bb58e34959a0ae229f340d61091ab726bbd3
hashf0062f7e70e61493684a2f60748a475168e155bc2502163c844c42e87692abd0

Ip

ValueDescriptionCopy
ip138.124.118.69
ip193.29.224.151
ip77.221.152.34

Url

ValueDescriptionCopy
urlhttp://193.29.224.151/92392991a0cca55?force=1

Domain

ValueDescriptionCopy
domainprofitnow.io

Threat ID: 6a75af5dbf8831d539217da3

Added to database: 08/07/2026, 10:11:41 UTC

Last enriched: 08/07/2026, 10:29:16 UTC

Last updated: 08/07/2026, 13:32:34 UTC

Views: 9

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses