A new macOS stealer is draining cryptocurrency wallets in small slices that victims are unlikely to notice.
Security firm Huntress documented the infection chain, and researcher Andrew Brandt said it starts when a web page tells a visitor to paste a command into Terminal, often to fix a supposed crash or pass a fake verification step.
The pasted command runs a Bash script that profiles the machine and pulls down a Go-based payload matched to its processor. That payload captures browser passwords, iCloud Keychain data and cached credentials, beaming them to an operator-controlled server, and it flashes a fake prompt about an unexpected system error to collect the user’s login credentials.
Inside the payload sits a function the researchers named DRAIN. When an installed wallet holds a balance, the code moves some or all of it to an address the attacker controls.
Separate functions exist for Bitcoin, Litecoin, Dogecoin, Monero, Ethereum and XRP, and one can compute what one percent of a wallet is worth, enabling a skim that leaves the account technically intact. Huntress said it has not previously seen a drainer that removes less than the entire balance.
Staging and command-and-control servers trace back to Aeza Group, a Russian bulletproof hosting provider sanctioned by the United States, the United Kingdom and Australia. The disclosure lands amid a busy stretch for ClickFix schemes, including a Microsoft-tracked macOS campaign delivering MacSync and Atomic Stealer.