Mac Malware Found Draining Crypto Wallets After Fake CAPTCHA Trick
Brief
Researchers at Huntress have uncovered a strain of macOS malware that can gradually siphon funds out of victims’ cryptocurrency wallets, after tracing an infection back to a fake CAPTCHA scam known as ClickFix.
The incident came to light during a retrospective threat hunt in June 2026, when a Huntress analyst discovered remnants of a Mac-specific stealer on a system that had actually been compromised three months earlier.
The victim had been served a pop-up disguised as a routine CAPTCHA check, instructing them to copy a command and paste it into the Mac Terminal application – a social engineering technique the security vendor says has surged in popularity in recent years.
Once executed, the command quietly pulled down a Bash loader that fingerprinted the machine before fetching a Go-based Mach-O payload tailored to the device’s processor architecture.
