Affected Systems

macOS users across all versions; targets cryptocurrency wallets (Bitcoin, Ethereum, Litecoin, Dogecoin, Monero, XRP), browser password databases, Apple Keychain, and cached browser credentials. Delivered via phishing emails with malicious Terminal commands.

Exploitation Status

Active campaign observed in the wild. Huntress MDR responded to live incident. Malware delivered via ClickFix social engineering technique using phishing emails that trick users into executing Terminal commands. Infrastructure hosted on Aeza Group (AS 210644), a sanctioned Russian bulletproof hosting provider.

Business Impact

Threat actors can steal cryptocurrency assets, browser-stored credentials, and Apple Keychain data from compromised macOS endpoints. Malware establishes persistence, escalates privileges via fake authentication prompts, and can selectively drain crypto wallets (partial or full). Bypasses Gatekeeper by removing quarantine attributes. Particularly dangerous for organizations with macOS users handling cryptocurrency or sensitive credentials. Detection gap: security teams alert on only 14% of successful attacks per industry data.

Urgency

🟠 Within 24 hours

Recommended Actions

  • ["Block outbound connections to AS 210644 (Aeza Group) at network perimeter and monitor for existing connections to this ASN"]
  • ["Deploy EDR rules to detect removal of com.apple.quarantine extended attributes and execution of binaries from directories mimicking system process names (e.g., trustd)"]
  • ["Monitor for osascript execution creating authentication dialogs outside normal system update workflows; alert on suspicious credential prompts"]
  • ["Educate macOS users on ClickFix social engineering: never paste commands from emails or websites into Terminal without verification"]
  • ["Audit macOS endpoints for persistence mechanisms in user LaunchAgents and unusual Mach-O binaries in user directories; hunt for files named com.apple.verified"]