# ClickFix attack pushes macOS infostealer for crypto theft attacks

> **Open Intelligence Dossier** · First detected: 2026-08-08 03:07 UTC · Category: Technology

## Executive Summary
A new wave of ClickFix attacks targets macOS users with fake CAPTCHAs to deploy infostealers designed to drain cryptocurrency wallets.

## Intelligence Brief
A sophisticated cyberattack campaign known as ClickFix is currently targeting macOS users to deploy infostealer malware. According to reporting from BleepingComputer and The Hacker News, these attacks are specifically designed to facilitate cryptocurrency theft. The primary mechanism involves a deceptive lure where users are presented with a fake CAPTCHA trick, as detailed by IT Security Guru. Once the user interacts with the fraudulent prompt, the malware is pushed to the system, allowing the attackers to access and drain the contents of cryptocurrency wallets stored on the device. Coverage from multiple cybersecurity entities emphasizes the technical evolution of these lures. Microsoft has highlighted the transition from open lures to what they describe as cloaked gates, illustrating how the campaign has learned to hide its activities.


The Hacker News reports that over 250 ClickFix domains are now utilizing browser fingerprinting techniques. This specific method allows the attackers to hide macOS malware lures from security researchers or automated scanners, ensuring that only the intended targets see the malicious prompts. This trend is significant because it challenges the common perception that Apple hardware is inherently immune to such threats. Bitdefender explicitly notes that using a Mac does not provide safety from ClickFix attacks. The context of this threat involves a shift toward social engineering where users are tricked into executing code via fake system errors or verification screens. The use of browser fingerprinting indicates a level of operational security by the threat actors, as they seek to avoid detection while scaling their infrastructure across hundreds of domains.


Future monitoring will likely focus on the proliferation of these cloaked domains and the evolving nature of the infostealer payloads. Based on the reports from Microsoft and BleepingComputer, the primary risk remains the delivery of the infostealer through deceptive browser interfaces. Security analysts will be watching for new variations of the CAPTCHA trick and updates on the number of domains involved in the campaign. The ability of the malware to target crypto wallets suggests that high-value digital assets remain the primary objective for the operators of the ClickFix campaign.

## Multi-Source Evidence Table
| Source Outlet | Headline | Verification URL |
|---|---|---|
| The Hacker News | ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets | [Source Link](https://news.google.com/rss/articles/CBMigwFBVV95cUxOMV96NUN3dXBHdHJST3ViOGw1ZmF2dGFEOVlvWkpIWUFzd2RvM0x5TjRpZEEzYmVSUlkwa1J3UkpRUDUyOW5qWk1VRUd2NmItZ2xXckxncGFEMW1UOHhTelFLUHAtczF1Y2lob2dJSXZzeWZsZFhialRGdGp5R3hJUG5POA?oc=5) |
| IT Security Guru | Mac Malware Found Draining Crypto Wallets After Fake CAPTCHA Trick | [Source Link](https://news.google.com/rss/articles/CBMirgFBVV95cUxOaFhUZXpZRXM0MWFyLW5jWGM1SnhhTjdnbG1Bdmp4dW5fekNPVTNTT28wcWxJT0lfcUc3b3p2R0p2VDJWcUZGeS1GQ2pLbldZSHRiWjlQc0k5QXJpclB0TjRUZnFnMlFUUEZ0Z0RaeFlNZFplcFcyLTk2WFdZVmRqM1JRZHRWSk5YcW5EVGxPc1d3eDB3XzhxQmNzaHlrOXlyLXFRYV9yaENQLUhCaUE?oc=5) |
| Bitdefender | Just because you use a Mac doesn't mean you're safe from ClickFix attacks | [Source Link](https://news.google.com/rss/articles/CBMiiwFBVV95cUxNQnF0ekhEZXJzU2IyOUhzMl9YaGRueDJUTzZfWVZtM1BVV1pVb1BTVEVkc2hQRnNNd2lDVnZLeUx2SjRCYnE1TlBoRFNNeGVSMGhOME9XUW1ERkVVTUlScjROZWg4MjNWLWNaR055SmEwazhYYXJyY1YzQ0dfNFYyN2JwNWRDRWlXT2V3?oc=5) |
| The Hacker News | Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures | [Source Link](https://news.google.com/rss/articles/CBMiggFBVV95cUxPRy1LeVMwR013SUVWcWJfUVFBT1dqODM3WERudXRZSThpcnZVUGtTdWpQN3daZm9ZaDhRTndrZnI0LWVuZ2VlUWNFc2N5c3BvRjdJMnBvQV9GcW11Ny1KYnpVSDFkd1JDX2Q1aEtHMS1CVGpkV1kzNDhRMDY1Z2k3bWJB?oc=5) |
| Microsoft | From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide | [Source Link](https://news.google.com/rss/articles/CBMimgFBVV95cUxNZjNBRGY5dENiZ0R5REhXVHpxTm5Cb0k0Y2pzZzFaaE01cTNYdmRjY3VORGtvTWxPTmw1WnhhN2otbU9KbkhnZDNPb2lFRmRKM3doSzRPSmJXMFlmWENfeGw4RTZMLVhjNGVRa3BEWUVXWkp1dndtM1V5WFdQUWVURHU5Q3F2dm1wbnBnQUdzX0pVQmo0MmE0dTJR?oc=5) |
| BleepingComputer | ClickFix attack pushes macOS infostealer for crypto theft attacks | [Source Link](https://news.google.com/rss/articles/CBMiswFBVV95cUxNVnNXOWVyYU9VM0trZWlVWTk3UHNGa2NNTnFRMUwzSWtQaTdqZ1B6Wl94NzdqODA1dlZpdHNWcGh0X0tpY0duYWg3OURmcmJsNVcxLWEtbzV6eGtZa1k5SHR0dXhMMkQ1TlpPeF9HNmdrTjU2Q3pOZzBQdWdDblBLZ3dTRksxSVZucW5aZjc5OHF5Z3pTSUptZElTUzE1R1RobGhQSnNHbGQ5azQ5d3ZQajc4ONIBuAFBVV95cUxOem9abjBmUW8zZ2JXYUNIUWdpQ0NOUFk1d0hzaVg5elVIYkJEcTdsT3o3Z01JWi1wLU9FQllyd1hnbG13cThzaUpwY25hLXBDM1pta3VIa1VTTnBlUEdvOWt6RzRoOG5nNUlvTFphM3NobnR5LU5KM2pjaVEyTnlhUjV4MFJ3NU1ocGdJRDhsQVYyUGtpV1lKTzl1YzZEM1p) |

---
*Canonical Source: https://pulse.byoviral.com/trend/2026-08-08/clickfix-attack-pushes-macos-infostealer-for-crypto-theft-attacks*
