Mac Malware Drains Crypto Wallets Via Fake CAPTCHA Scam
A sophisticated macOS malware campaign leverages ClickFix social engineering to infect victims. The attack begins with a fake CAPTCHA prompt delivered via email links, tricking users into executing malicious commands in Terminal. This downloads a profiling script that collects system information and deploys architecture-specific Go-based Mach-O payloads. The stealer targets browser passwords, Apple Keychain credentials, and cryptocurrency wallets. Its most notable feature is a DRAIN function that gradually siphons cryptocurrency from victims' wallets by redirecting portions to attacker-controlled accounts. The malware supports Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and XRP. Infrastructure analysis reveals hosting through Aeza Group, a sanctioned Russian bulletproof hosting provider. The malware achieves persistence through macOS Background Task Management and uses various evasion techniques including Gatekeeper bypass and credential harvesting via fake system prompts.
AI Analysis
Technical Summary
This sophisticated macOS malware campaign begins with social engineering via a fake CAPTCHA prompt sent through email links, tricking users into running commands in Terminal. The commands download a profiling script that collects system information and deploys architecture-specific Go-based Mach-O payloads. The malware steals browser passwords, Apple Keychain credentials, and cryptocurrency wallets. Its notable feature is a DRAIN function that gradually siphons cryptocurrency from victims’ wallets by redirecting portions to attacker-controlled accounts. Supported cryptocurrencies include Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and XRP. The malware maintains persistence through macOS Background Task Management and uses evasion techniques including Gatekeeper bypass and fake system prompts to harvest credentials. The hosting infrastructure is linked to Aeza Group, a known sanctioned Russian bulletproof hosting provider.
Potential Impact
The malware compromises macOS systems by stealing sensitive credentials including browser passwords and Apple Keychain data, as well as cryptocurrency wallet information. It enables attackers to gradually siphon cryptocurrency from victims’ wallets, potentially causing financial losses across multiple cryptocurrency types. The malware’s persistence and evasion techniques increase the difficulty of detection and removal, prolonging exposure and impact.
Mitigation Recommendations
No official patch or remediation is indicated. Mitigation should focus on user education to avoid executing commands from untrusted sources, especially those prompted by suspicious CAPTCHA-like social engineering. Monitoring for unusual background tasks and suspicious network connections to known malicious infrastructure (e.g., Aeza Group-hosted IPs and domains) may help detect infection. Use of endpoint protection solutions capable of detecting Mach-O payloads and credential-stealing behaviors is recommended. Since no vendor advisory or patch is available, users should remain vigilant and apply best practices for macOS security.
Indicators of Compromise
- hash: 39854a5f9c557b8e639bdb40f1866f4b
- hash: 504eea132c86ad37297dea78aa0e1143414d6300
- hash: 5bad988affc1094f12b8b8bed659ef55b20e2988eb25441e1c1b34dd03b3eb52
- hash: 619a99ba4ee9d7f33db8045c7e03c4265424977993fe8a53b0f45157c5abd3e5
- hash: b43a909a01e954d6549558f2f7e9bb58e34959a0ae229f340d61091ab726bbd3
- hash: f0062f7e70e61493684a2f60748a475168e155bc2502163c844c42e87692abd0
- ip: 138.124.118.69
- ip: 193.29.224.151
- ip: 77.221.152.34
- url: http://193.29.224.151/92392991a0cca55?force=1
- domain: profitnow.io
Mac Malware Drains Crypto Wallets Via Fake CAPTCHA Scam
Description
A sophisticated macOS malware campaign leverages ClickFix social engineering to infect victims. The attack begins with a fake CAPTCHA prompt delivered via email links, tricking users into executing malicious commands in Terminal. This downloads a profiling script that collects system information and deploys architecture-specific Go-based Mach-O payloads. The stealer targets browser passwords, Apple Keychain credentials, and cryptocurrency wallets. Its most notable feature is a DRAIN function that gradually siphons cryptocurrency from victims' wallets by redirecting portions to attacker-controlled accounts. The malware supports Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and XRP. Infrastructure analysis reveals hosting through Aeza Group, a sanctioned Russian bulletproof hosting provider. The malware achieves persistence through macOS Background Task Management and uses various evasion techniques including Gatekeeper bypass and credential harvesting via fake system prompts.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This sophisticated macOS malware campaign begins with social engineering via a fake CAPTCHA prompt sent through email links, tricking users into running commands in Terminal. The commands download a profiling script that collects system information and deploys architecture-specific Go-based Mach-O payloads. The malware steals browser passwords, Apple Keychain credentials, and cryptocurrency wallets. Its notable feature is a DRAIN function that gradually siphons cryptocurrency from victims’ wallets by redirecting portions to attacker-controlled accounts. Supported cryptocurrencies include Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and XRP. The malware maintains persistence through macOS Background Task Management and uses evasion techniques including Gatekeeper bypass and fake system prompts to harvest credentials. The hosting infrastructure is linked to Aeza Group, a known sanctioned Russian bulletproof hosting provider.
Potential Impact
The malware compromises macOS systems by stealing sensitive credentials including browser passwords and Apple Keychain data, as well as cryptocurrency wallet information. It enables attackers to gradually siphon cryptocurrency from victims’ wallets, potentially causing financial losses across multiple cryptocurrency types. The malware’s persistence and evasion techniques increase the difficulty of detection and removal, prolonging exposure and impact.
Defensive Guidance
No official patch or remediation is indicated. Mitigation should focus on user education to avoid executing commands from untrusted sources, especially those prompted by suspicious CAPTCHA-like social engineering. Monitoring for unusual background tasks and suspicious network connections to known malicious infrastructure (e.g., Aeza Group-hosted IPs and domains) may help detect infection. Use of endpoint protection solutions capable of detecting Mach-O payloads and credential-stealing behaviors is recommended. Since no vendor advisory or patch is available, users should remain vigilant and apply best practices for macOS security.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.huntress.com/blog/mac-crypto-draining-malware"]
- Adversary
- null
- Pulse Id
- 6a74c5ff523b6fcb70f5711d
- Threat Score
- null
Indicators of Compromise
Hash
| Value | Description | Copy |
|---|---|---|
hash39854a5f9c557b8e639bdb40f1866f4b | — | |
hash504eea132c86ad37297dea78aa0e1143414d6300 | — | |
hash5bad988affc1094f12b8b8bed659ef55b20e2988eb25441e1c1b34dd03b3eb52 | — | |
hash619a99ba4ee9d7f33db8045c7e03c4265424977993fe8a53b0f45157c5abd3e5 | — | |
hashb43a909a01e954d6549558f2f7e9bb58e34959a0ae229f340d61091ab726bbd3 | — | |
hashf0062f7e70e61493684a2f60748a475168e155bc2502163c844c42e87692abd0 | — |
Ip
| Value | Description | Copy |
|---|---|---|
ip138.124.118.69 | — | |
ip193.29.224.151 | — | |
ip77.221.152.34 | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttp://193.29.224.151/92392991a0cca55?force=1 | — |
Domain
| Value | Description | Copy |
|---|---|---|
domainprofitnow.io | — |
Threat ID: 6a75af5dbf8831d539217da3
Added to database: 08/07/2026, 10:11:41 UTC
Last enriched: 08/07/2026, 10:29:16 UTC
Last updated: 08/07/2026, 13:32:34 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.