# macOS Is Not Safe Harbor: ClickFix Campaign Pairs Crypto Draining With iCloud Keychain Theft
There's a particular kind of overconfidence that Mac users in crypto circles carry around. They didn't get ransomwared in 2017. They've never had to run Malwarebytes in a panic. The assumption hardens into identity: *my machine doesn't get infected.*
The threat actor behind a newly documented ClickFix campaign is counting on exactly that.
Huntress researcher Andrew Brandt published findings this week on a Go-based macOS stealer being delivered through ClickFix-style lures — the social engineering technique where victims are tricked into pasting a command into their own Terminal, handing the attacker execution with no exploit required. What makes this particular payload stand out isn't just the credential theft. It's a "DRAIN" routine that can partially siphon cryptocurrency wallets — not just wipe them clean, but quietly skim — across Bitcoin, Ethereum, Litecoin, Dogecoin, Monero, and XRP.
That distinction matters more than it might seem at first glance.
## How the Infection Chain Works
The attack is architecturally clean. Victim pastes a ClickFix command into Terminal. A Bash profiler runs first, collecting system information and CPU architecture. Then it fetches the appropriate Mach-O binary — compiled for either Apple Silicon or Intel — so the payload doesn't fail on the wrong hardware. That architecture-aware delivery isn't trivial; it signals a team that has thought through operational reliability.
The Go-based stealer that drops does what you'd expect: exfiltrates browser-stored passwords, scrapes Apple iCloud Keychain data, harvests cached credentials. To gain the elevated access needed for Keychain, it throws up a fake system dialog — "unexpected system error, restoring damaged system files" — and waits for the victim to type their password. A social engineering layer inside a social engineering attack.
Then the DRAIN routine runs. The malware checks whether any cryptocurrency wallets hold funds. If they do, it redirects a portion — or the whole balance — to attacker-controlled addresses. There are separate functions to calculate what 1% of a given wallet is worth in each supported currency. The malware doesn't have to be greedy to be dangerous.
The staging servers and C2 infrastructure trace back to Aeza Group, a Russian bulletproof hosting provider that the United States, United Kingdom, and Australia have all sanctioned for facilitating criminal operations. That's not background noise — it's the organizational signature of a well-resourced, persistent threat actor.
## The Partial Drain Is the Tell
Security practitioners tracking crypto-focused malware have seen wallet-wiping before. What Huntress flagged as a first here is the capacity for *fractional* draining — taking less than the full balance.
This isn't a technical novelty for its own sake. Draining a wallet completely is loud. A victim checks their balance, sees zero, knows immediately they've been hit, begins the incident response process. That raises the alarm before the attacker has necessarily exfiltrated everything else — the Keychain data, the browser cookies that might let them access exchanges directly, the credentials to cloud services.
Taking 10% or 20%, quietly, over time? That's a different threat model. The victim might not notice for days or weeks. By then the infrastructure has rotated, the attacker has moved laterally to other targets, and attribution gets harder.
Whether this group is actually running the fractional drain gradually or simply has the capability and uses it selectively — Huntress's report doesn't fully settle that — the capability being baked in tells you something about how this operation thinks about victim lifecycle management.
## ClickFix Is Now a Platform
This campaign doesn't exist in isolation. Three distinct ClickFix variants have surfaced in recent weeks, and the pattern they form together is worth naming explicitly: ClickFix has matured from a clever social engineering trick into an attack framework being actively developed across operators and platforms.
On macOS, a separate campaign distributes MacSync and Atomic Stealer using a cluster of lookalike domains with server-side browser fingerprinting and hardware validation — the lure is only served to visitors whose environment looks like a genuine macOS browser. Crawlers, sandboxes, and automated analysis tools get blocked. That's operational security thinking, not script-kiddie work.
On Windows, a ClickFix variant now abuses pcalua.exe — the Program Compatibility Assistant, a legitimate Windows binary — to bypass parent-process heuristics. The victim pastes a command, PowerShell spawns, WMI creates cmd.exe, a remote WebDAV share gets mounted over HTTPS via CDN-fronted infrastructure, and a malicious DLL loads through rundll32.exe. Each victim gets a tokenized UUIDv4 URL for delivery. That's per-victim infrastructure, which makes bulk detection significantly harder.
A third variant uses WebAssembly instantiation and SVG steganography to evade network-level detection entirely. The malicious JavaScript is injected into legitimate but compromised websites. The ClickFix URL gets constructed in-browser from SVG files. There's no single malicious domain to block because the content is distributed across the steganographic payload.
These aren't the same threat actor. But they're drinking from the same well — a technique that converts the victim's own terminal or command prompt into the attack surface, bypassing endpoint controls that assume malware arrives as an executable.
## HackWire Analysis
The Aeza Group connection puts this in a specific threat context that deserves more attention than most coverage has given it. Aeza isn't just bulletproof hosting in the abstract sense — it's an entity that three Western governments have concluded provides material support to criminal actors. When their infrastructure shows up in a campaign this technically refined, the operational picture isn't a lone developer experimenting with Go and crypto draining. It's a criminal services ecosystem: infrastructure-as-a-service layered under attack tooling that multiple operators are apparently refining in parallel.
The macOS specificity is deliberate. Apple's platform has a real security advantage in a lot of threat categories, but that advantage has calcified into a cultural assumption of immunity that ClickFix-style attacks are specifically designed to exploit. There's no exploit here. No zero-day. The victim runs the command themselves. No amount of Gatekeeper or SIP hardening prevents that.
What defenders — particularly in crypto-adjacent organizations and among high-net-worth individual Mac users — should take from this: Keychain data is not safe just because it's encrypted at rest. The fake system prompt attack against it is not new, but this campaign is among the more polished implementations targeting macOS specifically. Educate users, particularly those with significant crypto holdings, that no legitimate process will ever ask them to paste a command into Terminal from a webpage. That framing — "you were asked to paste a command" — is the detection signal.
The partial drain capability also has implications for crypto incident response. If you're investigating a potential compromise, a wallet that *seems* intact isn't clearance. Check transaction histories carefully. And if Keychain credentials were on the machine, assume exchange accounts are exposed regardless of wallet balances.
The ClickFix technique is being industrialized. That's the headline the individual campaign reports keep missing.
— HackWire Editorial
## Related Coverage