RESEARCHERS identified a new type of macOS malware designed to steal cryptocurrency and personal information. This malware is delivered through ClickFix social engineering attacks, manipulating users into executing malicious commands via a fake CAPTCHA prompt. The malware collects system details and scrapes browser passwords and Apple Keychain data, specifically targeting cryptocurrency wallets for theft. The exploitation method links back to the Aeza Group, a sanctioned Russian entity involved in cybercrime.
Prevention measures recommended include user education and browser add-ons to block malicious scripts, as well as immediate reporting to IT if an attack is suspected.