Wallet-Depleting macOS Malware Wants Your Crypto

    Date: 08/10/2026

    Severity: Medium

    Summary

    The macOS malware infection originated from a ClickFix social engineering scam.The attack delivered a shell script that collected basic system and device information. It then downloaded a macOS malware payload tailored to the computer’s CPU architecture. The malware can steal stored passwords and other sensitive information from the victim. It can also gradually drain cryptocurrency funds by transferring them to attacker-controlled wallets. The malware was hosted on an IP range linked to a Russian bulletproof hosting provider, sanctioned by the US and other countries in 2025.

    Indicators of Compromise (IOC) List

    Domains/URLs

    profitnow.io

    IP Address 

    193.29.224.151

    77.221.152.34

    138.124.118.69

    Hash  

    f0062f7e70e61493684a2f60748a475168e155bc2502163c844c42e87692abd0

    619a99ba4ee9d7f33db8045c7e03c4265424977993fe8a53b0f45157c5abd3e5

    5bad988affc1094f12b8b8bed659ef55b20e2988eb25441e1c1b34dd03b3eb52

    Filepaths 

    $HOME/Library/Caches/com.apple.trustd/com.apple.verified

    $HOME/Library/Caches/homeenergyd/com.apple.homeenergyd

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    domainname like "profitnow.io" or url like "profitnow.io" or siteurl like "profitnow.io"

    Detection Query 2 :

    dstipaddress IN ("193.29.224.151","138.124.118.69","77.221.152.34") or srcipaddress IN ("193.29.224.151","138.124.118.69","77.221.152.34")

    Detection Query 3 :

    sha256hash IN ("619a99ba4ee9d7f33db8045c7e03c4265424977993fe8a53b0f45157c5abd3e5","5bad988affc1094f12b8b8bed659ef55b20e2988eb25441e1c1b34dd03b3eb52","f0062f7e70e61493684a2f60748a475168e155bc2502163c844c42e87692abd0")

    Detection Query 4 :

    datasourcename = "Windows Security" and eventtype = "4663" and (objectname like "$HOME/Library/Caches/com.apple.trustd/com.apple.verified" or objectname like "$HOME/Library/Caches/homeenergyd/com.apple.homeenergyd")

    Detection Query 5 :

    technologygroup = "EDR" and (objectname like "$HOME/Library/Caches/com.apple.trustd/com.apple.verified" or objectname like "$HOME/Library/Caches/homeenergyd/com.apple.homeenergyd")

    Reference:    

    https://www.huntress.com/blog/mac-crypto-draining-malware                               


    Tags

    MalwareClickFixcryptocurrencySocial EngineeringCredential HarvestingRussiaUnited StatesFinancial Services

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags