clickfix
2 stories
ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets
A new Go-based malware targeting macOS is being distributed through ClickFix-style attacks. This malware is capable of stealing browser passwords, Apple Keychain data, and cached credentials. Notably, it also includes a function to gradually drain cryptocurrency wallets, siphoning funds into attacker-controlled accounts across various cryptocurrencies like Bitcoin, Ethereum, and XRP.

ClickFix to Cash-Out: Anatomy of a Mexican Banking-Fraud Toolkit
A sophisticated banking fraud operation, dubbed REF6045, utilizes a PowerShell toolkit named SCMBANKER, delivered via fake CAPTCHA pages. Unlike automated attacks, this operation is manually controlled, allowing operators to monitor victim banking sessions, deploy fake warnings, and manipulate browser activity. The toolkit also facilitates the installation of commercial remote access tools for full system takeover. Researchers discovered the operation through exposed directories and archives, revealing the use of AI-generated scripts and operator misconfigurations.