Mark RadarMARK RADAR
About
EN
Sign in
Event File CRYPTO Cryptocurrency Wallets

ClickFix Campaign Fingerprints Mac Users to Deliver Crypto-Stealing Malware

1 reports · First detected 2026-08-07 · Last active 2026-08-07

ClickFix is a social-engineering technique that presents bogus errors or CAPTCHA checks and persuades users to run commands on their own devices. Once largely associated with Windows, the method has increasingly targeted macOS without needing to exploit a software flaw. The user-initiated execution can sidestep conventional web defenses, allowing information stealers to pursue cryptocurrency wallets, browser passwords, session data and corporate credentials.

Microsoft said on Aug. 5, 2026 that the macOS campaign had used more than 250 domains and added a server-side browser-fingerprinting gate to screen out automated scanners and security sandboxes. Mac visitors who pass the checks are shown instructions to paste a malicious command into Terminal. That command ultimately installs Atomic macOS Stealer, or AMOS, which can harvest cryptocurrency-wallet data, account credentials and other sensitive information.

All Coverage

1 original reports

The Backstory

The history behind this event
ClickLock Mac Malware Targets Crypto Wallets Across 33 Countries2026-07-20 · 1 reports · similarity 0.82

ClickLock Stealer is a newly documented macOS information stealer that relies on social engineering rather than a software exploit. It is believed to arrive through ClickFix-style pages masquerading as Cloudflare verification checks, which persuade users to paste a malicious command into Terminal. The campaign matters because it turns trusted system prompts and built-in tools against Mac users, exposing browser credentials, password-manager data, Keychain material and cryptocurrency holdings while leaving a persistent backdoor.

Group-IB disclosed the malware on July 16, 2026, after finding a sample uploaded to VirusTotal on June 9 with zero detections at the time of analysis. The operation has been active since May and has targeted at least 100 victims in 33 countries, more than half in Europe. ClickLock can kill visible applications every 210 milliseconds until a user submits a login password, while harvesting data from 31 crypto-wallet browser extensions, eight desktop wallets and blockchain addresses across six networks for exfiltration through Telegram.

macOS Stealer Reaper Impersonates Tech Giants and Targets Crypto Wallets2026-05-19 · 2 reports · similarity 0.81

macOS users are increasingly being targeted by information-stealing malware, with attackers often posing as Apple, Microsoft or Google update alerts to lower their guard. Reaper is particularly significant because it both creates a system backdoor and targets cryptocurrency wallets such as MetaMask and Phantom, potentially gaining access to credentials, private keys and control of assets.

A cybersecurity company recently disclosed that Reaper uses a mix of fake Apple, Microsoft and Google software updates to trick macOS users into installing it, after which it collects wallet data and steals assets. Existing reports have not disclosed the organization that discovered it, the exact disclosure date, the number of victims or the value of losses. Users should update software only through official channels.

Fake CleanMyMac Campaign Steals Mac Users’ Crypto Wallet Data and Personal Information2026-03-10 · 1 reports · similarity 0.80

CleanMyMac is a macOS cleanup tool developed by MacPaw. Attackers created an imitation website and used ClickFix social engineering to trick users into pasting commands into Terminal, bypassing Gatekeeper, Apple notarization and XProtect. The threat is particularly serious because leaked recovery phrases could allow attackers to take direct control of wallet assets.

Malwarebytes disclosed on March 6, 2026, that the fake website, cleanmymacos.org, downloads SHub Stealer. The malware steals Apple Keychain contents, browser data and Telegram sessions, and scans for 23 wallet applications. It also tampers with applications including Ledger Live to capture recovery phrases. The report did not disclose the number of victims or the amount of losses.

Mark Radar|MARK RADAR
All times are in Taipei time (GMT+8)