Tuesday, April 21, 2026
cryptonews100
No Result
View All Result
CryptoNews100
No Result
View All Result
Home Cryptocurrency

macOS ClickFix attacks deliver AppleScript stealers • The Register

cryptonews100_tggfrn by cryptonews100_tggfrn
April 21, 2026
in Cryptocurrency
0
macOS ClickFix attacks deliver AppleScript stealers • The Register
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter
Sign up an get up to $1000 USDT!


A ClickFix marketing campaign concentrating on macOS customers delivers an AppleScript-based infostealer that collects credentials and stay session cookies from 14 browsers, 16 cryptocurrency wallets, and greater than 200 extensions.

Netskope Risk Labs researcher Jan Michael Alcantara advised The Register the crew initially observed the campaign final month, and has seen related cases as lately as final week.

ClickFix is a brilliant fashionable social engineering tactic used to trick folks into executing malicious instructions on their very own computer systems, often by clicking a faux pc downside repair or CAPTCHA immediate.

Whereas the researchers do not know who the cookie thief is, they notice the malware can infect each Home windows and macOS machines – Netskope beforehand warned in regards to the Windows-focused attacks – by utilizing a client-side JavaScript to filter victims by user-agent, ignoring cellular gadgets and directing desktop customers to both a Home windows or macOS-specific payload.

Victims, we’re advised, are in Asia and work within the finance sector.

Upon detecting a desktop surroundings, the malware directs customers to a faux CAPTCHA web page, performs one other inspection to find out the particular desktop OS, after which checks for macOS-specific strings inside the user-agent which can be used to load the AppleScript-based stealer.

The faux CAPTCHA prompts the person to open Highlight on their Mac, after which paste a “verification code” into the search characteristic. The phony code is a curl command, and as quickly because the sufferer hits Enter and executes it on their pc, the command silently downloads a malicious script from the attacker-controlled server. The script collects the sufferer’s username, hardcodes the command-and-control (C2) server deal with, and creates a short lived listing at /tmp/xdivcmp/ to stage all the stolen knowledge earlier than sending it to the C2.

Apple didn’t reply to The Register‘s inquiries for this story, nevertheless it’s vital to notice that the newest variations of macOS Tahoe (26.4) or macOS Sequoia embody a brand new characteristic designed to dam ClickFix attacks. It alerts customers after they try to stick doubtlessly malicious instructions into the Terminal software, so replace your working system to assist detect and stop some of these ClickFix attacks.

But when a person is operating an older OS model, or for some motive ignores the macOS warning and clicks the “paste anyway” choice, the malware strikes on to the credential-harvesting stage by deploying a really sneaky social engineering dialog field that masses the genuine macOS system lock icon from native assets. Customers see the lock, suppose it is a legit Apple dialog field, after which enter their system password.

The malware additionally takes excessive measures to power credential entry. It solely has a single motion button – there is no choice for customers to shut the dialog field window – and it retains reappearing till the sufferer enters a sound password. 

That is what the malware steals

Person passwords are validated in actual time, utilizing macOS’s listing companies authentication, and if incorrect, the dialog field reappears, with this loop persevering with till the individual gives an accurate password.

Subsequent, it snarfs up all types of person knowledge, together with the macOS Keychain (which shops saved passwords, Wi-Fi credentials, safe notes, and cryptographic keys), whereas the malicious dialog loop captures the sufferer’s password in plaintext.

The stealer additionally targets 12 Chromium-based browsers: Chrome, Courageous, Edge, Vivaldi, Opera, Opera GX, Chrome Beta, Chrome Canary, Chromium, Chrome Dev, Arc, and CocCoc. For every of those, it searches person profiles and steals session tokens, authentication cookies, saved passwords and different autofill data together with bank card numbers, knowledge from greater than 200 browser extensions, and extension databases.

This browser-extension theft is very insidious because the miscreants’ malware is configured to swipe particulars from cryptocurrency wallets together with MetaMask, Phantom, Coinbase Pockets, Belief Pockets, and dozens of blockchain-specific ones. It additionally collects password supervisor credentials from LastPass, 1Password, Dashlane, Bitwarden, two-factor authentication apps together with Authy and Google Authenticator extensions, and numerous VPN and single sign-on extensions used for company entry.

Along with the Chromium browser knowledge, the malware steals cookie databases, form-autofill knowledge, grasp passwords, and saved credentials from Firefox and Waterfox, one other Firefox-based browser.

And past browser extensions, the stealer targets 16 standalone desktop cryptocurrency pockets functions: Exodus, Atomic, Electrum, Coinomi, Guarda, Ledger Stay, Trezor Suite, Bitcoin Core, Litecoin Core, Sprint Core, Dogecoin Core, Monero, Wasabi, Sparrow, Electron Money, and Electrum-LTC.

Alcantara advised us that this infostealer marketing campaign is unrelated to 1 that additionally focused macOS customers’ credentials and cryptocurrency wallets that Microsoft final week attributed to North Korean criminals regardless of related methods – corresponding to utilizing social engineering even when malware is operating.

Netskope has revealed a full checklist of indicators of compromise and scripts associated to this malware in its GitHub repository, so give {that a} learn. And because the risk hunters notice, “this marketing campaign serves as a reminder that social engineering stays a major risk to each Home windows and macOS customers.” ®



Source link

Related articles

SEC warns vs cryptocurrency platforms

SEC warns vs cryptocurrency platforms

April 21, 2026

South Korea’s National Tax Service Fully Tracks Cryptocurrency Tax Evasion, Including Non-Custodial Wallets | Blockchain 24/7 News – Blockchain Project Updates – Fintech News – Crypto Art News

April 21, 2026
Tags: AppleScriptattacksClickFixDelivermacOSRegisterstealers
Share76Tweet47
Drive and walk to earn crypto!

Related Posts

SEC warns vs cryptocurrency platforms

SEC warns vs cryptocurrency platforms

by cryptonews100_tggfrn
April 21, 2026
0

THE Securities and Change Fee (SEC) has warned the general public towards unregistered cryptocurrency buying and selling platforms, saying these...

South Korea’s National Tax Service Fully Tracks Cryptocurrency Tax Evasion, Including Non-Custodial Wallets | Blockchain 24/7 News – Blockchain Project Updates – Fintech News – Crypto Art News

by cryptonews100_tggfrn
April 21, 2026
0

TechFlow News, April 21: In response to ZDNet Korea, South Korea’s National Tax Service (NTS) issued a young discover on...

World Liberty Financial Analysis: Is WLFI a Good Investment in 2026?

U.S. Senator pushes to extend the review of the cryptocurrency market structure bill to May to allow more time for discussions on the stablecoin proposal

by cryptonews100_tggfrn
April 21, 2026
0

The privacy-focused crypto pockets Mixin introduced in the present day the launch of its U-based perpetual contract (a by-product priced...

Best free cryptocurrency cloud mining apps of 2026: Earn Bitcoin easily on Android and iOS

Best free cryptocurrency cloud mining apps of 2026: Earn Bitcoin easily on Android and iOS

by cryptonews100_tggfrn
April 20, 2026
0

Cloud mining has turn into one of essentially the most searched subjects within the cryptocurrency subject, as extra and extra...

Altcoins May Be Beneficiaries of Bitcoin Resurgence

Altcoins May Be Beneficiaries of Bitcoin Resurgence

by cryptonews100_tggfrn
April 20, 2026
0

Bitcoin’s newest rally nonetheless faces some checks. Nevertheless, the biggest cryptocurrency’s rebound could renewing animal spirits within the crypto universe. If...

Load More

Crypto Fear & Greed Index

Latest Crypto Fear & Greed Index

Recent News

macOS ClickFix attacks deliver AppleScript stealers • The Register

macOS ClickFix attacks deliver AppleScript stealers • The Register

April 21, 2026
Bitmine Immersion Pushes Ether Holdings Near 5M ETH

Bitmine Immersion Pushes Ether Holdings Near 5M ETH

April 21, 2026
BTC Binance Inflows Drop As Coinbase Activity Rises

BTC Binance Inflows Drop As Coinbase Activity Rises

April 21, 2026

Categories

  • Bitcoin
  • Cardano
  • Chainlink
  • Cryptocurrency
  • Dogecoin
  • Ethereum
  • Exchanges
  • Pokadot
  • Polygon
  • Real World Assets
  • Shiba Inu
  • Solana
  • sui
  • World Liberty Financial
  • XRP

Download the official CryptoNews100 Android App! Click the button below:

Tags

ADA (111) billion (79) Bitcoin (718) Breakout (79) BTC (161) Buy (126) Cardano (202) ChainLink (163) crypto (707) Cryptocurrency (222) DOGE (75) Dogecoin (232) ETF (122) ETH (114) Ethereum (371) eyes (82) gains (87) Inu (156) Iran (79) key (81) launches (109) Liberty (80) market (262) million (91) News (353) PEPETO (100) Polkadot (124) POLYGON (107) prediction (243) Presale (79) price (613) rally (103) Recovery (82) Ripple (74) RWA (126) Shiba (165) Solana (205) Stablecoin (79) Sui (148) today (86) top (163) TradingView (170) Trump (101) world (96) XRP (408)

© 2023 Crypto News100 All Rights Reserved.
By visiting this website, you understand that the content provided within is for educational and entertainment purposes only. Nothing on this site may be constituted as financial advice and this site is not directing you to make any investments in cryptocurrency or in anything else. Thank you for visiting and please proceed responsibly.
As an Amazon Associate I earn from qualifying purchases.

No Result
View All Result
  • Home
  • Bitcoin
  • Ethereum
  • Alt Coins
    • Cardano
    • Dogecoin
    • Pokadot
    • Polygon
    • Shiba Inu
    • Solana
    • XRP
  • Crypto Related DEALS

© 2023 Crypto News100 All Rights Reserved.
By visiting this website, you understand that the content provided within is for educational and entertainment purposes only. Nothing on this site may be constituted as financial advice and this site is not directing you to make any investments in cryptocurrency or in anything else. Thank you for visiting and please proceed responsibly.
As an Amazon Associate I earn from qualifying purchases.