
The Huntress research team has discovered new malware targeting Mac computers. Scammers trick users into copying a one-line command and pasting it into the Terminal application.
Key points to know:
• This tactic is called ClickFix — a fake pop-up asking you to copy code to “fix” an issue or verify your identity.
• Once the code is pasted and executed, it steals saved browser passwords and iCloud Keychain data.
• A DRAIN feature extracts funds from crypto wallets, including Bitcoin, Ethereum, XRP, and Monero.
• It can siphon off as little as 1% at a time to prevent wallet owners from noticing quickly.
[Insight: No legitimate company will ever ask you to copy commands into Terminal to watch a video or verify your identity. If you see this, close it immediately.]
Kun Long
Author at The Sharing KH