# The Pickpocket in Your Keychain: A macOS Infostealer That Steals Just Enough to Stay Hidden
A new piece of macOS malware discovered by Huntress does something unusual for a crypto thief: it doesn't take everything. It takes enough. That restraint is the most sophisticated thing about it — and the reason defenders should be paying attention.
The payload, a Go-based infostealer delivered through ClickFix social engineering, was caught mid-operation when Huntress MDR researchers responded to an incident earlier this month. What they found goes well beyond another credential scraper. This malware reads your wallet, calculates percentages, and drains a configured slice of your holdings — leaving the rest behind so you don't immediately notice the balance change.
## Terminal as the Attack Surface
ClickFix attacks work by convincing users to do the attacker's job for them. The target in this case received an email linking to a page that instructed them to run a command in Terminal. No exploit required, no zero-day needed. The user pastes a command and hits return.
What executes is a Bash script functioning as a profiler and staged loader. It collects system telemetry — CPU, RAM, architecture — and uses that information to pull down a Mach-O payload compiled for the victim's processor. Intel and Apple Silicon variants are handled separately. The operation is built for scale.
This delivery mechanism deserves emphasis: ClickFix works because the user is the trusted process. There's nothing for an EDR to flag when a human being opens Terminal and types a command. The social engineering layer is the bypass.
## Dressed as Apple's Own Plumbing
Once the payload lands, the masquerade begins. The malware creates a persistence directory named after trustd — the legitimate macOS process responsible for validating cryptographic certificates and code signatures. The payload itself is copied there as com.apple.verified. The naming convention is not accidental. On a quick inspection, both the folder name and filename look like Apple infrastructure.
Before execution, the malware strips the com.apple.quarantine extended attribute from the payload. This is the attribute that triggers Gatekeeper's "are you sure?" dialog when a file downloaded from the internet is opened. Removing it silently kills the warning. The binary runs clean.
To escalate privileges, the malware generates a fake system error using osascript — macOS's built-in scripting utility — displaying a dialog box prompting the user for their administrator password. It looks like an authentic system prompt. Once the user enters their credentials, the malware has what it needs.
## The Patient Drain
The stealer component is thorough. It targets browser password databases, Apple Keychain, cookies, and cached credentials across browsers. That's roughly expected at this point in the macOS stealer ecosystem. What distinguishes this payload is the crypto module.
Huntress notes this is the first time they've analyzed a crypto drainer configured for partial extraction. The malware includes logic to calculate 1% of a wallet's holdings per currency type, and can be configured to redirect any percentage of a transaction to attacker-controlled addresses before it's signed. The theft happens at the transaction layer — the funds leave during what appears to be a normal operation.
The supported currencies cover most of what retail crypto holders actually hold: Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and XRP. Monero's inclusion is notable given its privacy properties, though transaction interception before signing would bypass anonymity features regardless.
The strategic logic of partial draining is sound from the attacker's perspective. A wallet emptied overnight generates an immediate incident report, possibly a police complaint, and almost certainly account freezes. A wallet that loses 15% over three transactions might go unnoticed for weeks — plenty of time for the malware to remain installed and operational.
## Where the C2 Traffic Goes
The malware phones home to IP addresses within Autonomous System 210644, operated by Aeza Group. This Russian corporation has been sanctioned by both the United States and the United Kingdom for providing bulletproof hosting services to ransomware operators. The infrastructure isn't new to cybercrime — it's a known address on the threat landscape, the kind of hosting that doesn't respond to abuse reports and doesn't care who its customers are.
The Aeza connection places this campaign in a specific tier of threat actors: organized, resourced, and protected by jurisdictional distance. These aren't opportunistic script kiddies. The development work — Go-based cross-architecture compilation, fake Apple process names, Gatekeeper bypass, partial drain logic — reflects engineering investment.
---
## HackWire Analysis
The partial drain capability deserves more attention than it's getting in initial reporting, because it marks a maturation point in crypto-targeting malware that has real operational implications.
For years, the signature of a crypto stealer was catastrophic and immediate: empty wallet, panicked victim, instant detection. The problem with that approach — from the attacker's perspective — is that it generates heat. Fast. Victims call exchanges, freeze accounts, and sometimes have enough blockchain forensics pointing back at the operation to cause real problems.
Configurable partial extraction changes the risk calculus. An attacker running this at scale across hundreds of infected machines, each draining 10–20% of holdings per month, generates far less incident volume than the same operation run as a grab-and-go. Victims are more likely to attribute small unexplained losses to market volatility, fee structures, or their own accounting errors. The malware persists. The drain continues.
This also reflects a broader shift in macOS targeting that's been building since 2023. The platform's reputation for security has made it a soft target in a specific way: users trust it too much. The false sense of safety that macOS's market share once provided — "not worth targeting" — evaporated alongside its growth in enterprise and crypto-holder demographics. Atomic Stealer, Cuckoo, Banshee, and now this unnamed Go-based payload represent a sustained campaign to catch up to the Windows stealer ecosystem.
For defenders: the ClickFix vector is the hardest part to block technically because user execution is the mechanism. The controls that actually work are training (never run Terminal commands from a webpage), application controls to alert on unexpected quarantine attribute removal, and behavioral monitoring for osascript spawning fake dialogs. If you're in an environment with crypto-holding employees on macOS, that last one alone is worth adding to your detection stack today.
The Aeza Group infrastructure connection is also worth tracking. Security teams with threat intel feeds should flag traffic to AS210644 as high-confidence malicious. The same hosting environment servicing ransomware groups is now servicing infostealers — the operational separation may be thinner than it looks.
— HackWire Editorial
---
## Related Coverage