<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Stealer-Malware on CuraSec</title><link>https://curasec.metacog.co.kr/tags/stealer-malware/</link><description>Recent content in Stealer-Malware on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 09 Aug 2026 11:41:42 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/stealer-malware/index.xml" rel="self" type="application/rss+xml"/><item><title>ClickFix macOS Stealer Targets Crypto, Keychain, Browser Creds</title><link>https://curasec.metacog.co.kr/insights/2026-08-09-clickfix-attacks-deliver-macos-stealer-that-can-drain-crypto/</link><pubDate>Sun, 09 Aug 2026 11:41:42 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-09-clickfix-attacks-deliver-macos-stealer-that-can-drain-crypto/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> No KEV, PoC, or active enterprise exploitation signals; this is a socially-engineered user-side attack. Worth noting if your org has mac-heavy developer populations with crypto assets or shared Keychain credentials that could pivot to cloud access.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> ClickFix lures dropping shell scripts followed by architecture-aware macOS payloads represent a detectable chain — build or tune detections for unexpected shell script execution on macOS endpoints followed by outbound connections, and verify EDR coverage for macOS stealer behavior (Keychain access, browser credential reads).&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item></channel></rss>