New Mac Malware Uses Fake 'Fix It' Prompts to Steal Crypto and Passwords
Security researchers have identified a new wave of 'ClickFix' style attacks targeting Mac computers with malware written in the Go programming language. These attacks typically trick users into copying and pasting a command into their computer's terminal, often under the guise of fixing an error or verifying they are human.
Once triggered, the malicious script checks details about the victim's Mac, including its processor type, before downloading a tailored malware payload. This payload is designed to harvest sensitive information such as browser-saved passwords, data stored in Apple's iCloud Keychain, cached login credentials, and cryptocurrency wallet assets.
Because the attack relies on tricking a person into manually running a command, rather than exploiting a technical software flaw, it can bypass many traditional security protections. This makes staff awareness the most important line of defence against this type of threat.