Connect with us

Infosecurity

New Go-Based macOS Malware Targets Crypto Wallets and Keychain Data

Published

on

Go-based macOS malware

Go-Based macOS Malware: A New Threat Emerges

Security researchers at Huntress have uncovered a new strain of infostealing malware designed specifically for macOS. This Go-based macOS malware operates through ClickFix social engineering attacks, a technique that tricks users into executing malicious commands disguised as CAPTCHA prompts.

First identified in June 2026, this malware represents a significant escalation in the sophistication of macOS-targeted threats. Unlike typical malware that requires exploiting system vulnerabilities, this attack relies on human error—a far more unpredictable and effective vector.

How ClickFix Attacks Deliver the Malware

The attack begins with a popup window that appears to be a legitimate CAPTCHA challenge. Users are instructed to copy a long command string and paste it into the Terminal application. This command downloads and executes the initial stage of the attack.

According to Huntress, the command pulls a Bash profiler/loader that collects system details before fetching a Mac-native Mach-O payload matched to the victim’s processor architecture. Mach-O is the executable format used by macOS, and in this case, the Go-based stealer was built to scrape browser password stores, Apple Keychain data, and cached credentials from the infected system.

The Role of Go in the Malware

Go, also known as Golang, has become a popular language for malware development due to its cross-platform capabilities and ease of compiling for different architectures. This particular Go-based macOS malware is a prime example, as it can be tailored to run efficiently on both Intel and Apple Silicon Macs.

Crypto Wallet Drain Function

One of the most concerning features of this malware is its DRAIN function. This capability checks whether a cryptocurrency wallet holds funds and then redirects all or part of that balance to attacker-controlled wallets. This makes the malware particularly dangerous for individuals and organizations that hold digital assets.

“The malware also included a DRAIN function that could check whether a cryptocurrency wallet held funds, then redirected all or part of that balance to attacker-controlled wallets,” the Huntress blog post stated.

Attribution to Aeza Group

The loader, payload hosting, and command and control (C2) infrastructure all link back to the Aeza Group, a sanctioned Russian bulletproof hoster associated with cybercrime. This attribution highlights the ongoing threat from state-aligned or state-tolerant cybercriminal networks.

Bulletproof hosters like Aeza Group provide infrastructure that is resistant to law enforcement takedowns, making them a preferred choice for cybercriminals seeking long-term operational stability.

Mitigation and Response Strategies

Huntress advises organizations to mitigate ClickFix threats through user education and by installing malicious script mitigation browser add-ons like NoScript. Additionally, network devices like Pi-Hole DNS can reduce the chances of popups appearing by blocking known-bad domains from resolving through DNS blocking.

“If a user inadvertently follows through with a ClickFix exploit, it is imperative that the user inform their IT team immediately and that the machine be brought into an isolation mode,” the researchers concluded.

“The malware may or may not achieve persistence, but it is easily remediated by deleting any copies of the binary left behind on the machine. Once deleted, the malware will not spontaneously reconstitute itself.”

Practical Steps for Users

  • Always verify the legitimacy of CAPTCHA prompts, especially those that ask you to run commands in Terminal.
  • Use browser extensions like NoScript to block unauthorized scripts.
  • Implement DNS-level filtering to block known malicious domains.
  • Regularly back up important data and maintain offline copies.
  • If you suspect a ClickFix attack, disconnect from the network and contact your IT department immediately.

For more on protecting your systems, consider reading about macOS security best practices and ClickFix attack prevention.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Infosecurity

Ghostjacking: How Your Own AI Agents Can Silently Gut Your Firewall

Published

on

Ghostjacking AI attack

The Illusion of a Secure Perimeter

Your firewall is up. Logs are clean. The bad guys are outside. That’s the comfortable story — and it’s exactly what a new attack technique called Ghostjacking exploits.

Half of the Fortune 500 runs setups that could be silently gutted by their own AI coding agents, according to research from Tenet Security presented at DEFCON 2026 in Las Vegas on August 9. The trick isn’t breaking in. It’s making the company’s own trusted tools open the door from the inside.

The researchers showed how a single fake bug report can hijack an AI assistant, reroute email and web traffic, and leave a backdoor that survives cleanup. The firewall doesn’t even go down. It just becomes irrelevant.

How Ghostjacking Works: A Fake Report Becomes a Real Command

Here’s the core problem: AI agents can’t tell the difference between a genuine instruction and a trap hidden in data they’re told to read. Tenet calls this the next evolution of the ‘Agentjacking’ attack class, where coding assistants are tricked into running arbitrary code.

The attack chain is deceptively simple. With Cloudflare‘s firewall, when a malicious request is blocked, the system logs it word-for-word. An attacker plants a fake log entry. Later, when an analyst asks the AI to review blocked events, the agent reads that planted entry as if it were a real finding. The AI then rewrites the company’s DNS, points the domain at the attacker, and reports the issue as resolved. Traffic and emails quietly reroute.

“It is Cloudflare’s managed security rule that blocks the request, and that block is what carries the attack in,” Tenet said.

Datadog and Sentry: The Same Shape, Different Doors

The pattern repeats elsewhere. Datadog keys meant only for front-end use are routinely left public — Tenet found over 2,700 of them. Those keys let an attacker plant a fake “urgent diagnostic alert” that the AI agent reads when an engineer asks it to check for errors.

With Sentry, the researchers went further. They used Sentry’s own AI, Seer, to vouch for their fake fix. Seer reads the planted report and the attacker’s malicious patch, then presents it as its own conclusion to the coding agent. The agent trusts Seer, runs the code, and the machine is compromised.

“Sentry, Cloudflare, and Datadog are not three separate flaws. They are the same shape,” the researchers noted. “An AI reads outside data it trusts, and the same AI can also act on it. Wherever those two things meet, the door is open.”

The Scope: Why This Matters for Fortune 500 Companies

The exposure isn’t hypothetical. Cloudflare runs in 42% of Fortune 500 firms and carries a fifth of all internet traffic. Datadog is present in 48% of those companies. Sentry is used by four million developers.

Tenet demonstrated the technique succeeded nine out of ten times against the Claude Code AI agent, on Cloudflare’s own recommended setup. Among the organizations running that exact exposed configuration are a trillion-dollar global tech company, a major payments provider, and a leading AI research lab.

The attack also leaves persistent access. Attackers can embed backdoors in the agent’s configuration, memory, and tools — enabling data theft, credential harvesting, and long-term espionage. In one demonstration, the team even got one AI agent to build an attack that another AI would accept. They called it a “self-exploit.”

What Companies Can Do Right Now

Tenet reported the findings to Sentry, Datadog, and Cloudflare in June. But the researchers stress that patching these specific platforms won’t end the problem. The underlying flaw — AI agents trusting external data — is structural.

They recommend four concrete actions to reduce exposure:

  • Deny outbound network access by default. This alone stops both the attacker’s download and the data leak.
  • Require human approval for any command the agent wants to run.
  • Never let data an agent reads become an instruction it runs. Separate input channels from execution channels.
  • Assume any reachable token is at risk. Review every tool the agent connects to, and rotate credentials aggressively.

The uncomfortable truth is that AI agents are being handed keys to the kingdom — and they can’t tell a legitimate order from a poisoned log entry. Until that changes, the firewall is just a decorative wall.

Continue Reading

Infosecurity

US Sanctions Iranian Crypto Exchange Shelbit Over $6bn in Suspicious Flows

Published

on

Iranian crypto exchange Shelbit

The US Treasury has sanctioned an Iranian crypto exchange accused of moving over $6 billion in illicit blockchain funds over two years.

Shelbit, a Dubai-registered platform that never held a license, has been hit with sanctions by the US Treasury Department’s Office of Foreign Assets Control (OFAC). The action also targets its founder, Siavash Kayvanpour, and a network of affiliated entities spread across the UAE, Poland, and Georgia. A separate Iran-based exchange, Aban Tether, was sanctioned too.

The move follows a detailed investigation by blockchain analytics firm TRM Labs, which published its findings on August 7. The firm’s report paints a stark picture: Shelbit was not a real exchange. It was a settlement conduit, a pipe for moving money.

According to TRM, between May 2024 and March 2026, Shelbit processed roughly $6.3 billion. Nearly all of it flowed to wallets controlled by the Islamic Revolutionary Guard Corps (IRGC). The scale is staggering. That’s more than $3 million per day, every day, for two years.

How Shelbit Worked: A Conduit, Not an Exchange

The analytics firm’s report shows that Shelbit’s wallets held virtually no balances at any given time. Money came in and went out almost immediately. Inbound and outbound amounts matched to within 0.1% — a pattern that screams settlement infrastructure, not a customer-facing exchange.

TRM Labs noted that this kind of precision matching is consistent with a platform designed to move value quickly, not to hold customer funds. It’s a technique used to obscure the trail.

The bulk of the activity — about 88%, or $5.6 billion — moved on the TRON blockchain, almost entirely in dollar-pegged stablecoins. The average transfer was around $54,500. That’s a lot of small, steady movements.

Wallet Rotation to Avoid Detection

Shelbit rebuilt its wallet infrastructure every one to four months across its two years of operation. TRM called this a deliberate effort to limit traceability. It’s a common tactic among illicit crypto services — constantly shifting addresses makes it harder for analytics firms and law enforcement to follow the money.

The platform also had direct connections to terrorism financing. In September, Shelbit apparently sent over $2 million in four transfers on a single day to a wallet controlled by Hamas.

Beyond the IRGC: Russian Sanctioned Networks and Gambling

The sanctions aren’t just about Iran. TRM traced $318 million from Shelbit to A7, a sanctioned Russian payment network. The exchange also had exposure to Grinex, Rapira, and other sanctioned Russian and Central Asian services. This was a multi-sanctioned-economy operation.

But the most intriguing finding is who Shelbit’s main customers were. TRM identified a Farsi-language online gambling network of more than 2,000 websites as the primary user base. That’s not a typo. Two thousand separate betting sites.

Two Iranian social media figures front these sites publicly. Sasha Sobhani, the son of a former senior Iranian diplomat and government minister, posts from a villa in Madrid. Pooyan Mokhtari, an influencer and singer, promotes the betting sites to his millions of followers. Both advertise conspicuous wealth, with links to betting sites pinned at the top of their profiles.

Both deny any wrongdoing. Sobhani says he categorically rejects involvement in money laundering, sanctions evasion, or terrorism financing, and that his role was limited to paid advertising. Mokhtari denies the allegations in Dubai and says he has no affiliation with the IRGC. Both say they never knew Kayvanpour and were unfamiliar with Shelbit. Kayvanpour has not responded to requests for comment.

What the Sanctions Mean

TRM traced around $72.6 million in exposure between Shelbit and online gambling services across 55 separate platforms. The largest single relationship accounted for approximately $46.4 million.

Treasury Secretary Scott Bessent issued a statement with the sanctions. He framed the action as part of a broader pressure campaign. “The Iranian regime’s reliance on digital assets and shadow banking networks is further evidence that Economic Fury is working,” he said. “We will continue to increase the economic pressure. Whether in dollars, rials, or crypto, Treasury will hunt down and dismantle the illicit financial networks that keep the regime afloat.”

This action is part of a larger pattern. Crypto sanctions have become a key tool in US financial warfare. A leaked database earlier this year shed light on how Iranian entities use crypto to evade sanctions. The Shelbit case shows the scale of the problem — and the sophistication of the networks involved.

For anyone tracking Iran crypto sanctions evasion, this is a major data point. It demonstrates that illicit crypto flows are not just a niche concern. They’re a systemic issue, involving gambling networks, terrorist financing, and sanctioned state actors across multiple jurisdictions.

The sanctions freeze any US-based assets of the designated entities and prohibit US persons from doing business with them. But the question remains: how many other Shelbits are out there, quietly moving billions through the shadows?

Continue Reading

Infosecurity

Britain’s Next War Won’t Be an Away Game: A Q&A with the Former Head of Defence Intelligence

Published

on

Britain's next war

A Warning from the Shadows

General Sir Jim Hockenhull spent a career inside Britain’s military intelligence establishment. Yet he might be best remembered for giving secrets away.

As Chief of Defence Intelligence from December 2018 to May 2022, he made the call to declassify and publish London’s knowledge of Russia’s invasion plans—down to a map of the routes its forces would take. The goal was to expose the Kremlin’s intentions before Moscow could manufacture a pretext. The move is now widely seen as a success, though Hockenhull admits that when he first proposed it, almost no one in government thought it was a good idea.

Now out of uniform since June, he’s speaking with a new urgency. His message is blunt: Britain’s next war won’t be an away game. It will be fought at home, in cyberspace, and on the information front—long before any tanks roll.

The One Man Who Said Yes

In 2023, at Recorded Future’s Predict conference, Hockenhull revealed that only one person had backed his radical plan to publish intelligence. That person was Ben Wallace, the then-Defence Secretary.

“I was lucky it was him,” Hockenhull says now.

Bureaucracy, he explains, is designed to manage risk. “People tend not to say yes or no to anything. They’ll say, ‘that’s an interesting idea,’ and then ask lots of questions. If you’re not careful, you screen out the things that could be really good but are quite risky.”

Wallace was different. He understood intelligence from his time as security minister, and he was willing to take big decisions. “If you went to him with a reasoned argument, he’d back you. That’s why, with one person, we got it through.”

From Ultra to Open Source

The contrast with the Second World War is stark. Britain went to extraordinary lengths to conceal intelligence sources like Ultra. In 2022, Hockenhull made the opposite choice.

He sees it as a continuum. “It’s all the use of intelligence,” he says. The question is which direction you go, because once you commit, you’re committed. The first release on Feb. 17, 2022, showed the axes of Putin’s invasion plan. But it couldn’t be a one-off. A discrete team was set up to work out what could be shared publicly without compromising sources and methods.

The public releases were only part of a wider effort. For a long time, London didn’t make clear it was also sharing a great deal with the Ukrainians. “The conflict is broader than what happens on the ground. It’s in the information space, and it always has been.”

The arrival of the iPhone changed everything, he argues. “Suddenly everybody’s consuming information in a fundamentally different way. This was our first attempt to recognize that we’re in a modern digital era of communication.”

Deterrence Is Stuck in the 1950s

Who was the disclosure aimed at? All of them—the British public, allies, Ukraine, and Russia. The emphasis shifted over time.

“We wanted the British public to understand that a war was coming in Europe, that it was a long-planned Russian effort,” he says. The playbook was familiar—Georgia in 2008, Ukraine in 2014, Syria in 2016—but it had never been contested in advance.

That raises a wider question about deterrence. “We often revert to nuclear deterrence theory of the 1950s,” Hockenhull says. “But in the modern age, how do we use our insight, our knowledge dominance, to deter our adversaries?”

The key is that these aren’t psychological operations. “This is using the truth to let people know the real situation before Russian falsehoods take hold, because once a lie is established, it gains a life of its own and is almost impossible to kill.”

The Limits of Intelligence

Many assessments suggested Kyiv would fall quickly. It didn’t. Does that complicate the idea that 2022 was an intelligence success?

Hockenhull is candid. “The key insight we had was understanding the Russian plan for Kyiv to fall in five to seven days. What we understood less clearly was how Ukraine intended to fight.” The Ukrainians were loath to share their plans with anyone, sometimes even among themselves.

About a week before the invasion, his team wrote an assessment highlighting Russia’s weaknesses: an operation at a scale not attempted since WWII, logistics not well supported, a reliance on very quick success, challenging command and control, questionable morale, poorly trained conscripts. “What we didn’t imagine was that Russia would fall over all of them simultaneously.”

There’s a deeper point here. “When you use intelligence, you change the situation. By informing the people mounting the operations, they act on it, and that changes the context being assessed.” In other words, part of the reason it didn’t happen is the insight intelligence provided.

Cyber: Not Weapons, Lego Bricks

The new Defence Investment Plan focuses heavily on cyber defense rather than offense. Hockenhull isn’t surprised. The big investment in the National Cyber Force was made back in 2021 and guaranteed over a decade.

He rejects the idea of a cyber silver bullet. “A conventional weapon stays broadly the same object until it’s used. Cyber terrain changes continuously—someone updating their system could remove an opportunity, create a new one, or change the risk.”

His metaphor is telling: “Cyber tools are less like weapons in a warehouse and more like Lego bricks. Skilled people can combine them in different ways, but the usefulness of any combination depends on the target, the technology and the moment.”

This is where he sometimes admires Britain’s adversaries. “Not the methods, the risks, or the ethical bounds they storm through—but the way they use everything as tools of statecraft.” Britain, by contrast, is a responsive nation, dealing with everything below the threshold of war as separate incidents.

Successive governments have tried to build campaigns, but “government is very good at reorganizing itself, and that makes sustained campaigning over a long period difficult.” Spending-review budgets run only four years, and people at the top shift and move. “If we’re going to adopt a longer-term campaigning approach, we need consistency, in resourcing but also in intent and structure.”

The Digital Targeting Web

The Digital Targeting Web in the DIP reminds him of the Dowding System from the Battle of Britain: gather information, combine it, make a decision and act. The underlying logic isn’t new. What’s changed is the scale, speed and complexity.

“Modern forces can gather extraordinary amounts of information. The challenge is to make sense of it in space and time, then act at the speed of relevance.”

The real ambition is broader than “any sensor to any shooter.” It’s “anybody’s sensor to anybody’s shooter.” A Royal Navy system might detect a threat that’s then struck by a Netherlands Air Force aircraft. That raises hard questions of trust and law. “Am I going to take action that may kill someone, based on information from another country, trusting their process was sound? If the missile’s inbound, there may be no time for a second check.”

The First Battle: Talent

Hockenhull has said the battle for digital and cyber talent is the first battle of the next war. Britain is making progress, but it’s a work in progress.

For most of his career, people joined the Army, Navy or Air Force through traditional routes and only later moved into cyber. So they created a direct pathway. The first cohort did a short period of basic military training and then went straight into specialist cyber instruction. They joined in August and graduated in November.

The first group was small—about 40 people—but only one dropped out. “That’s far below the normal attrition in military training. We were reaching highly motivated people who might never have joined through the conventional system.”

The traditionalists don’t always welcome variation. “They’ve got a big sausage machine to run, and it’s easier to limit the variation. But for scarce digital skills, we have to be more flexible.”

Why the Public Must Know

Hockenhull’s final argument returns to where he began. Britain is attacked in cyberspace every day. It may face sabotage, espionage and attacks on its undersea cables long before anything resembling a shooting war. Yet almost everything the state knows about that threat stays classified.

That leaves people being asked to fund the response—with money that would otherwise go to schools and hospitals—largely on trust. “We assume the public understands the connection, but if our insight stays highly classified, we’re effectively asking people to trust us without seeing the evidence.”

Repeating that war is possible isn’t enough. “Particularly when more defense spending may mean less for a child’s education, or a longer wait for an NHS operation. That’s an asymmetric argument, and we’ve got to do much better.”

He wants a coalition, inside and outside government, willing to have a national conversation over time. “We jumped from the Strategic Defence Review straight to funding, and almost skipped the people who matter most—the ones who’ll pay for it and live with the consequences.”

His final warning is simple and stark: “Because war isn’t going to happen as an away game. If there is a conflict, it will be happening here.”

Continue Reading

Trending