SECURITY·중요도 8·2026. 08. 07.·The Hacker News

ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets

── KO ──────────────────

ClickFix 공격이 macOS 스틸러를 배포하여 암호화폐 지갑을 탈취합니다.

ClickFix 공격 방식이 macOS 플랫폼을 겨냥하여 암호화폐 자산을 탈취하는 Go기반의 악성코드를 전달하고 있습니다. 이 악성코드는 브라우저에 저장된 비밀번호, Apple iCloud 키체인 데이터 및 캐시된 인증 정보를 훔칠 수 있는 기능을 가지고 있습니다. 감염 체인은 호스트를 프로파일링한 후 해당 컴퓨터의 CPU 아키텍처에 호환되는 macOS 악성 페이로드를 가져오는 쉘 스크립트를 배포하도록 설계되었습니다.


── EN ──────────────────

ClickFix attacks are delivering a macOS stealer capable of draining cryptocurrency wallets.

ClickFix-style attacks are being employed to deliver a Go-based malware that targets macOS systems for stealing cryptocurrency assets. This malware can also siphon browser-stored passwords, Apple iCloud Keychain data, and cached credentials. The infection chain works by profiling the host and then fetching a macOS malware payload compatible with the computer's CPU architecture.

원문 보기 →목록으로