Scan to download
BTC $81,441.09 +1.00%
ETH $2,356.85 +1.46%
BNB $656.92 +1.64%
XRP $1.46 +3.20%
SOL $96.06 +3.38%
TRX $0.3497 -0.16%
DOGE $0.1106 +2.44%
ADA $0.2801 +3.93%
BCH $460.40 +2.36%
LINK $10.67 +3.38%
HYPE $42.58 -0.11%
AAVE $101.08 +6.08%
SUI $1.33 +24.56%
XLM $0.1675 +3.74%
ZEC $580.54 -3.07%
BTC $81,441.09 +1.00%
ETH $2,356.85 +1.46%
BNB $656.92 +1.64%
XRP $1.46 +3.20%
SOL $96.06 +3.38%
TRX $0.3497 -0.16%
DOGE $0.1106 +2.44%
ADA $0.2801 +3.93%
BCH $460.40 +2.36%
LINK $10.67 +3.38%
HYPE $42.58 -0.11%
AAVE $101.08 +6.08%
SUI $1.33 +24.56%
XLM $0.1675 +3.74%
ZEC $580.54 -3.07%

Microsoft Security Team: Fake macOS troubleshooting posts install cryptocurrency wallet stealers

2026-05-11 08:04:56
Collection

According to market news, Microsoft's security research team has discovered that attackers have been inducing users to run malicious terminal commands by publishing fake macOS troubleshooting guides since the end of 2025, thereby stealing cryptocurrency wallets, iCloud data, and passwords saved in browsers.

These fake guides are published on platforms such as Medium, Craft, and Squarespace, targeting common user issues like freeing up disk space or fixing system errors, and tricking users into copying and pasting malicious commands into the terminal, which automatically downloads and runs malware. This social engineering technique, named ClickFix, bypasses macOS's Gatekeeper security mechanism because the victims are actively executing the commands.

The malware families involved include AMOS, Macsync, and SHub Stealer, which can steal cryptocurrency wallet keys from Exodus, Ledger, and Trezor, as well as usernames and passwords saved in Chrome and Firefox. In some cases, attackers also delete legitimate wallet applications and replace them with trojan versions. Apple has added a protective feature in macOS version 26.4 to prevent the pasting of potentially malicious commands.

app_icon
ChainCatcher Building the Web3 world with innovations.