← BACK TO FEED
TAG

lumma stealer1 article

ClickFix Malware Can Slowly Bleed Your Crypto Wallet Dry

ClickFix-style attacks are being used to deliver a Go-based macOS malware that steals browser passwords, Apple Keychain data, and cryptocurrency wallet contents, with the ability to gradually drain funds across multiple cryptocurrencies including Bitcoin, Ethereum, and Monero. The attack tricks victims into pasting a command into Terminal, which profiles the system, downloads a compatible payload, and uses a fake error prompt to harvest system credentials. The malicious infrastructure is linked to Aeza Group, a Russian bulletproof hosting provider sanctioned by the US, UK, and Australia.

8 Aug 2026