{"id":897,"date":"2026-08-07T11:33:45","date_gmt":"2026-08-07T06:03:45","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=897"},"modified":"2026-08-19T11:34:17","modified_gmt":"2026-08-19T06:04:17","slug":"clickfix-macos-malware-steals-keychain-data-drains-crypto","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/clickfix-macos-malware-steals-keychain-data-drains-crypto\/","title":{"rendered":"ClickFix macOS Malware Steals Keychain Data, Drains Crypto"},"content":{"rendered":"<p>Huntress has documented a ClickFix macOS malware campaign that tricks users into pasting a Terminal command from a fake verification prompt. The Go-based stealer harvests browser passwords, Keychain data, and cached credentials, and can quietly redirect part or all of a cryptocurrency wallet&#8217;s balance to attacker-controlled addresses.<\/p>\n<p>Huntress found the <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-malware\/\">malware<\/a> during a June 2026 retrospective threat hunt, on a system infected roughly three months earlier, and published its analysis on August 6. BleepingComputer reported the findings the same day.<\/p>\n<p>For enterprise teams, the case shows macOS endpoints remain exposed to social engineering that never touches a malicious attachment. A single pasted command can expose Keychain data, drain crypto wallets, and hijack cached browser sessions.<\/p>\n<p><center>    \t\t<!-- button style scb20be917a3efc78059cf9961ee4e54284 -->\r\n    \t\t<style>\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284, a.scb20be917a3efc78059cf9961ee4e54284{\r\n    \t\t\t\tcolor: #fff;\r\n    \t\t\t\tbackground-color: #00868B;\r\n    \t\t\t}\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284:hover, a.scb20be917a3efc78059cf9961ee4e54284:hover{\r\n    \t\t\t\t    \t\t\t\tbackground-color: #32b8bd;\r\n    \t\t\t}\r\n    \t\t<\/style>\r\n    \t\t<a href=\"https:\/\/www.hexnode.com\/\" class=\"ht-shortcodes-button scb20be917a3efc78059cf9961ee4e54284  hn-cta__blogs--inline-button \" id=\"\" style=\"\" >\r\n    \t\tBook a free demo and explore Hexnode today!<\/a>\r\n    \t\t<\/center><\/p>\n<h2>A fake CAPTCHA prompt, then a Terminal Command<\/h2>\n<p>The infection began when the target clicked an email link. The page showed a fake CAPTCHA popup instructing them to paste a command into Terminal, the core ClickFix mechanic: execution shifts from a downloaded file to something the victim types themselves.<\/p>\n<p>The command pulled a file from an attacker IP, ran it, deleted itself, then cleared the Terminal window and history, leaving few visible traces.<\/p>\n<p>That file was a Bash profiler and loader. It collected hardware identifiers, RAM, CPU details, and the username, checked whether the processor was ARM64 or x86_64, then fetched the matching Mach-O payload. Huntress notes ClickFix has surged in popularity and appears in many variants it tracks.<\/p>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-challenges.jpeg?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>Top 10 Cybersecurity Challenges for Enterprises<\/h4><p>Top 10 enterprise cybersecurity challenges, causes, and Hexnode's mitigation strategies.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/top-10-cybersecurity-challenges-for-enterprises\/\" aria-label=\"Top 10 Cybersecurity Challenges for Enterprises\"><\/a><\/div><\/div><\/div>\n<h3>Additional details from Huntress&#8217;s investigation:<\/h3>\n<p>The ClickFix page used the domain profitnow[.]io during the initial lure stage.<\/p>\n<p>One IP address hosted the loader, while a separate IP address in the same hosting range served the final payloads, splitting delivery across two hosts.<\/p>\n<p>Two distinct Mach-O binaries sat on that infrastructure at the same time, one built for ARM64 and the other for x86_64, so the operators had pre-staged payloads for both Apple Silicon and Intel Macs before profiling any victim.<\/p>\n<h2>Hiding behind Apple&#8217;s own naming conventions<\/h2>\n<p>With the ClickFix macOS malware in place, the loader script copied the payload into a cache directory named after trustd, Apple&#8217;s certificate-validation process, then renamed it com.apple.verified. The script also stripped the quarantine attribute to avoid a Gatekeeper flag.<\/p>\n<p>A second payload, staged under a com.apple.softwareupdate path, had its attributes removed and was ad hoc signed. It was then registered as a launch agent through Background Task Management to persist after a restart. The malware also used osascript, a legitimate automation tool, to display a fake password prompt and capture the victim&#8217;s credentials.<\/p>\n<table style=\"width: 100%;\">\n<thead>\n<tr>\n<th style=\"width: 23.7844%; text-align: left;\">Attack Stage<\/th>\n<th style=\"width: 37.9492%; text-align: left;\">What Happened<\/th>\n<th style=\"width: 37.2094%; text-align: left;\">Operational Risk<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"width: 23.7844%;\"><a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-initial-access-in-cybersecurity\/\">Initial access<\/a><\/td>\n<td style=\"width: 37.9492%;\">Email link led to a fake CAPTCHA popup instructing a Terminal command<\/td>\n<td style=\"width: 37.2094%;\">Bypasses attachment-based email defenses entirely<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 23.7844%;\">Profiling and delivery<\/td>\n<td style=\"width: 37.9492%;\">Bash loader profiled the Mac and fetched an architecture-matched Mach-O payload<\/td>\n<td style=\"width: 37.2094%;\">Confirms active, device-tailored payload delivery<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 23.7844%;\">Staging and evasion<\/td>\n<td style=\"width: 37.9492%;\">Payload copied into a trustd-named directory, quarantine attribute stripped<\/td>\n<td style=\"width: 37.2094%;\">Reduces the Gatekeeper warnings admins rely on<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 23.7844%;\">Privilege elevation<\/td>\n<td style=\"width: 37.9492%;\">Fake osascript prompt captured the victim&#8217;s password<\/td>\n<td style=\"width: 37.2094%;\">Extends attacker access beyond the initial session<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 23.7844%;\">Credential and wallet theft<\/td>\n<td style=\"width: 37.9492%;\">Stealer harvested browser and Keychain data; DRAIN function intercepted crypto transactions<\/td>\n<td style=\"width: 37.2094%;\">Exposes stored credentials and cryptocurrency holdings<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 23.7844%;\">Infrastructure<\/td>\n<td style=\"width: 37.9492%;\">Loader, hosting, and C2 traced to Aeza Group, sanctioned by the US and UK in July 2025<\/td>\n<td style=\"width: 37.2094%;\">Links the incident to established bulletproof hosting<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>What this ClickFix macOS malware actually takes<\/h2>\n<ul>\n<li>Browser password databases, identified by file name and extension across common browser install paths.<\/li>\n<li>Apple Keychain data, giving attackers access to stored system and application credentials.<\/li>\n<li>Cached browser cookies, which can enable session hijacking without needing a fresh login.<\/li>\n<li>Cryptocurrency wallet balances, through a DRAIN function that checks wallet holdings before redirecting funds.<\/li>\n<li>A configurable percentage of each transaction, rather than the full balance, which Huntress said is the first crypto drainer it has analyzed that&#8217;s capable of taking less than a wallet&#8217;s full value.<\/li>\n<\/ul>\n<p>The stealer supports Bitcoin, Litecoin, Dogecoin, Ethereum, and XRP, using distinct code for the Bitcoin-based currencies, Ethereum, and XRP.<\/p>\n<h2>Securing the Mac fleet against ClickFix-style attacks<\/h2>\n<p><a href=\"https:\/\/www.hexnode.com\/uem\/\">Hexnode UEM<\/a> gives Mac fleets concrete controls here. Google Santa enforces application allowlisting, blocking unsigned Mach-O binaries in disguised cache folders. CrowdStrike Falcon and SentinelOne add behavioral detection for suspicious process activity. Privacy Preferences Policy Control lets admins manage app access to protected macOS services like Camera, Screen Recording, and Full Disk Access on behalf of users. Firewall, FileVault, and patch enforcement round out the baseline.<\/p>\n<p><a href=\"https:\/\/www.hexnode.com\/xdr\/\">Hexnode XDR<\/a> adds unified incident visibility, a dashboard view of <a href=\"https:\/\/www.hexnode.com\/blogs\/mitre-attack-framework\/\">MITRE ATT&amp;CK<\/a> events, and one-click response, process kill, file quarantine, endpoint isolation, alongside UEM. This is established on Windows today. Hexnode&#8217;s help documentation does not yet describe macOS support for XDR.<\/p>\n<ul>\n<li>Google Santa allowlisting blocks unsigned binaries before execution<\/li>\n<li>CrowdStrike Falcon or SentinelOne detect suspicious process activity<\/li>\n<li>Privacy Preferences Policy Control restricts Apple Events, blunting osascript prompts<\/li>\n<li>Hexnode XDR&#8217;s unified dashboard and one-click response, documented for Windows endpoints<\/li>\n<\/ul>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/The-cybersecurity-blueprint.png?format=webp\" class=\"resource-box__image\" alt=\"the cybersecurity blueprint\" loading=\"lazy\" srcset=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/The-cybersecurity-blueprint.png?format=webp 960w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/The-cybersecurity-blueprint-300x225.png?format=webp 300w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/The-cybersecurity-blueprint-768x576.png?format=webp 768w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/The-cybersecurity-blueprint-133x100.png?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"the cybersecurity blueprint\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            The Cybersecurity Blueprint\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Guide to choosing and implementing an effective cybersecurity strategy, covering statistics, frameworks, and organizational steps.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/white-papers\/the-cybersecurity-blueprint-how-to-adopt-the-right-cybersecurity-strategy-for-your-business\/'>\n                            DOWNLOAD\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<div class=\"faq-section-wrapper\" itemscope itemtype=\"https:\/\/schema.org\/FAQPage\"><h2 class=\"faq-main-title\">FAQs<\/h2><div class=\"faq-items\"><div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Did stripping the quarantine attribute help evade detection here?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Not meaningfully. Huntress notes curl doesn&#8217;t set the quarantine attribute in the first place, making this step largely redundant here, though it remains standard evasion in loaders that use tools which do apply the flag.<\/p>\n<\/div><\/div><\/div> <div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Is the crypto-draining function present in every version?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Yes. Huntress found DRAIN compiled into both the ARM64 and x86_64 builds, with a DRAIN_PCT setting controlling how much of a wallet gets redirected rather than always draining it fully.<\/p>\n<\/div><\/div><\/div>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Does this malware always establish persistence?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Not always, per Huntress. When it does, it registers a launch agent through Background Task Management to survive a restart.<\/p>\n<\/div><\/div><\/div><\/div><\/div>\n<h3>Conclusion<\/h3>\n<p>The more distinctive lesson from this ClickFix macOS malware campaign isn&#8217;t a new exploit. It&#8217;s how convincingly the malware blends into Apple&#8217;s own process names and automation tools to avoid a second look. Any Mac can be talked into running a Terminal command, no vulnerability required.<\/p>\n<p>Security teams should treat unsolicited Terminal instructions as a hard stop, no matter how legitimate the prompt looks. Pairing user education with macOS-specific hardening and third-party detection tooling remains the most practical way to catch what native defenses and email filters miss.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Stop ClickFix before it reaches Terminal. <\/h5><p>Harden Mac fleets with Hexnode UEM and layered macOS endpoint security today. <\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> SIGN UP NOW<\/a><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Huntress has documented a ClickFix macOS malware campaign that tricks users into pasting a Terminal&#8230;<\/p>\n","protected":false},"author":5,"featured_media":899,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[15,17],"class_list":["post-897","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-malware","category-macos","product_category-identity-provider","tab_group-identity-and-phishing"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>ClickFix macOS Malware: Crypto Drainer Targets Keychain Data<\/title>\n<meta name=\"description\" content=\"ClickFix macOS malware steals Apple Keychain data and browser credentials, then drains cryptocurrency wallets, according to Huntress research.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/clickfix-macos-malware-steals-keychain-data-drains-crypto\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"ClickFix macOS Malware: Crypto Drainer Targets Keychain Data\" \/>\n<meta property=\"og:description\" content=\"ClickFix macOS malware steals Apple Keychain data and browser credentials, then drains cryptocurrency wallets, according to Huntress research.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/clickfix-macos-malware-steals-keychain-data-drains-crypto\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-07T06:03:45+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-19T06:04:17+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/clickfix-macos-malware.jpeg?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"700\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Sophia Hart\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Sophia Hart\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/clickfix-macos-malware-steals-keychain-data-drains-crypto\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/clickfix-macos-malware-steals-keychain-data-drains-crypto\\\/\"},\"author\":{\"name\":\"Sophia Hart\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/7303d7e90665b5fbccde155fa1c11430\"},\"headline\":\"ClickFix macOS Malware Steals Keychain Data, Drains Crypto\",\"datePublished\":\"2026-08-07T06:03:45+00:00\",\"dateModified\":\"2026-08-19T06:04:17+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/clickfix-macos-malware-steals-keychain-data-drains-crypto\\\/\"},\"wordCount\":1099,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/clickfix-macos-malware-steals-keychain-data-drains-crypto\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/clickfix-macos-malware.jpeg?format=webp\",\"articleSection\":[\"Malware\",\"macOS\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/clickfix-macos-malware-steals-keychain-data-drains-crypto\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/clickfix-macos-malware-steals-keychain-data-drains-crypto\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/clickfix-macos-malware-steals-keychain-data-drains-crypto\\\/\",\"name\":\"ClickFix macOS Malware: Crypto Drainer Targets Keychain Data\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/clickfix-macos-malware-steals-keychain-data-drains-crypto\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/clickfix-macos-malware-steals-keychain-data-drains-crypto\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/clickfix-macos-malware.jpeg?format=webp\",\"datePublished\":\"2026-08-07T06:03:45+00:00\",\"dateModified\":\"2026-08-19T06:04:17+00:00\",\"description\":\"ClickFix macOS malware steals Apple Keychain data and browser credentials, then drains cryptocurrency wallets, according to Huntress research.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/clickfix-macos-malware-steals-keychain-data-drains-crypto\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/clickfix-macos-malware-steals-keychain-data-drains-crypto\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/clickfix-macos-malware-steals-keychain-data-drains-crypto\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/clickfix-macos-malware.jpeg?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/clickfix-macos-malware.jpeg?format=webp\",\"width\":1340,\"height\":700,\"caption\":\"clickfix macos malware\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/clickfix-macos-malware-steals-keychain-data-drains-crypto\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"ClickFix macOS Malware Steals Keychain Data, Drains Crypto\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/7303d7e90665b5fbccde155fa1c11430\",\"name\":\"Sophia Hart\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"caption\":\"Sophia Hart\"},\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/sophia-hart\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"ClickFix macOS Malware: Crypto Drainer Targets Keychain Data","description":"ClickFix macOS malware steals Apple Keychain data and browser credentials, then drains cryptocurrency wallets, according to Huntress research.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/clickfix-macos-malware-steals-keychain-data-drains-crypto\/","og_locale":"en_US","og_type":"article","og_title":"ClickFix macOS Malware: Crypto Drainer Targets Keychain Data","og_description":"ClickFix macOS malware steals Apple Keychain data and browser credentials, then drains cryptocurrency wallets, according to Huntress research.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/clickfix-macos-malware-steals-keychain-data-drains-crypto\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-08-07T06:03:45+00:00","article_modified_time":"2026-08-19T06:04:17+00:00","og_image":[{"width":1340,"height":700,"url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/clickfix-macos-malware.jpeg?format=webp","type":"image\/jpeg"}],"author":"Sophia Hart","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Sophia Hart","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/clickfix-macos-malware-steals-keychain-data-drains-crypto\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/clickfix-macos-malware-steals-keychain-data-drains-crypto\/"},"author":{"name":"Sophia Hart","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/7303d7e90665b5fbccde155fa1c11430"},"headline":"ClickFix macOS Malware Steals Keychain Data, Drains Crypto","datePublished":"2026-08-07T06:03:45+00:00","dateModified":"2026-08-19T06:04:17+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/clickfix-macos-malware-steals-keychain-data-drains-crypto\/"},"wordCount":1099,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/clickfix-macos-malware-steals-keychain-data-drains-crypto\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/clickfix-macos-malware.jpeg?format=webp","articleSection":["Malware","macOS"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/clickfix-macos-malware-steals-keychain-data-drains-crypto\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/clickfix-macos-malware-steals-keychain-data-drains-crypto\/","url":"https:\/\/www.hexnode.com\/threat-watch\/clickfix-macos-malware-steals-keychain-data-drains-crypto\/","name":"ClickFix macOS Malware: Crypto Drainer Targets Keychain Data","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/clickfix-macos-malware-steals-keychain-data-drains-crypto\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/clickfix-macos-malware-steals-keychain-data-drains-crypto\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/clickfix-macos-malware.jpeg?format=webp","datePublished":"2026-08-07T06:03:45+00:00","dateModified":"2026-08-19T06:04:17+00:00","description":"ClickFix macOS malware steals Apple Keychain data and browser credentials, then drains cryptocurrency wallets, according to Huntress research.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/clickfix-macos-malware-steals-keychain-data-drains-crypto\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/clickfix-macos-malware-steals-keychain-data-drains-crypto\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/clickfix-macos-malware-steals-keychain-data-drains-crypto\/#primaryimage","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/clickfix-macos-malware.jpeg?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/clickfix-macos-malware.jpeg?format=webp","width":1340,"height":700,"caption":"clickfix macos malware"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/clickfix-macos-malware-steals-keychain-data-drains-crypto\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"ClickFix macOS Malware Steals Keychain Data, Drains Crypto"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/7303d7e90665b5fbccde155fa1c11430","name":"Sophia Hart","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","caption":"Sophia Hart"},"url":"https:\/\/www.hexnode.com\/threat-watch\/author\/sophia-hart\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/897","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=897"}],"version-history":[{"count":2,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/897\/revisions"}],"predecessor-version":[{"id":902,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/897\/revisions\/902"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/899"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=897"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=897"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}