Date: 08/10/2026
Severity: Medium
Summary
The macOS malware infection originated from a ClickFix social engineering scam.The attack delivered a shell script that collected basic system and device information. It then downloaded a macOS malware payload tailored to the computer’s CPU architecture. The malware can steal stored passwords and other sensitive information from the victim. It can also gradually drain cryptocurrency funds by transferring them to attacker-controlled wallets. The malware was hosted on an IP range linked to a Russian bulletproof hosting provider, sanctioned by the US and other countries in 2025.
Indicators of Compromise (IOC) List
Domains/URLs | profitnow.io |
IP Address | 193.29.224.151 77.221.152.34 138.124.118.69 |
Hash | f0062f7e70e61493684a2f60748a475168e155bc2502163c844c42e87692abd0
619a99ba4ee9d7f33db8045c7e03c4265424977993fe8a53b0f45157c5abd3e5
5bad988affc1094f12b8b8bed659ef55b20e2988eb25441e1c1b34dd03b3eb52
|
Filepaths | $HOME/Library/Caches/com.apple.trustd/com.apple.verified $HOME/Library/Caches/homeenergyd/com.apple.homeenergyd |
Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection
Detection Query 1 : | domainname like "profitnow.io" or url like "profitnow.io" or siteurl like "profitnow.io" |
Detection Query 2 : | dstipaddress IN ("193.29.224.151","138.124.118.69","77.221.152.34") or srcipaddress IN ("193.29.224.151","138.124.118.69","77.221.152.34") |
Detection Query 3 : | sha256hash IN ("619a99ba4ee9d7f33db8045c7e03c4265424977993fe8a53b0f45157c5abd3e5","5bad988affc1094f12b8b8bed659ef55b20e2988eb25441e1c1b34dd03b3eb52","f0062f7e70e61493684a2f60748a475168e155bc2502163c844c42e87692abd0")
|
Detection Query 4 : | datasourcename = "Windows Security" and eventtype = "4663" and (objectname like "$HOME/Library/Caches/com.apple.trustd/com.apple.verified" or objectname like "$HOME/Library/Caches/homeenergyd/com.apple.homeenergyd") |
Detection Query 5 : | technologygroup = "EDR" and (objectname like "$HOME/Library/Caches/com.apple.trustd/com.apple.verified" or objectname like "$HOME/Library/Caches/homeenergyd/com.apple.homeenergyd") |
Reference:
https://www.huntress.com/blog/mac-crypto-draining-malware