{
  "id": 1430817,
  "title": "Go malware targets Mac crypto wallets and credentials",
  "url": "https://urgent.news/2026/08/17/go-malware-targets-mac-crypto-wallets-and-credentials",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-17T05:06:33.000Z",
  "source": {
    "name": "Arabian Post",
    "slug": "arabian-post",
    "url": "https://thearabianpost.com/go-malware-targets-mac-crypto-wallets-and-credentials/"
  },
  "original_language": "en",
  "account": "A new macOS malware, written in Go and compiled as a Mach-O executable, is specifically targeting cryptocurrency wallets, credentials, and Apple Keychain data. This malware is delivered through ClickFix social engineering attacks, where victims are tricked into copying and pasting malicious commands into Terminal. Once executed, the malware can steal browser credentials, cached authentication data, and manipulate cryptocurrency transactions. Its distinctive feature is the ability to siphon part or all of a victim's cryptocurrency balance, rather than just emptying a wallet. The malware searches for browser passwords, Apple Keychain information, browser cookies, and other files containing cached credentials. It can also target specific cryptocurrencies such as Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and XRP. The malware was discovered while investigating an infection where a Mac user clicked a link delivered via email. ClickFix campaigns typically involve fake verification messages, troubleshooting instructions, or CAPTCHA-like prompts that trick users into executing commands themselves, rather than relying on conventional software installers or exploitable vulnerabilities. Threat groups have increasingly adopted this approach, distributing information stealers through fake maintenance guides, system optimization pages, and other seemingly helpful content. The malware uses Go Garbler, a tool that obfuscates strings inside compiled Go programs, making it more difficult for analysts and security products to examine. Researchers identified hardcoded attacker-controlled addresses in the malware samples, but the financial scale of the operation remains unclear due to the absence of publicly visible addresses. The malware was distributed by the Aeza Group network, a bulletproof hosting operation linked to cybercrime and ransomware activity.",
  "summary": "A newly analysed macOS information-stealing malware is targeting cryptocurrency holdings, passwords and Apple Keychain data after victims are tricked into executing malicious commands through ClickFix social-engineering attacks. The malware, written in the Go programming language and compiled as a native Mach-O executable, can steal browser credentials and cached authentication data while also…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}