Atlas21
  • ‎
No Result
View All Result
Atlas21
No Result
View All Result
Atlas21
Home Bitcoin

macOS: fake CAPTCHA pages install malware to steal crypto

Newsroom by Newsroom
March 30, 2026
in Bitcoin
macOS: falsi CAPTCHA installano malware per rubare criptovalute
Share on FacebookShare on TwitterShare on Linkedin

A new infostealer called Infiniti Stealer targets Mac users through fake CAPTCHA pages that trick victims into running dangerous commands in the Terminal.

Security researchers at Malwarebytes have identified a new malicious campaign targeting crypto users on macOS. The attack exploits fake CAPTCHA pages that mimic the Cloudflare verification system to trick victims into installing an infostealer called Infiniti Stealer, designed to steal crypto wallet data, credentials, and other sensitive information from Apple computers.

The attack falls under the ClickFix category – a social engineering technique in which the user is manipulated into executing the malicious command themselves. The process begins with a fake page hosted on update-check[.]com, which faithfully replicates the appearance of a Cloudflare verification screen. After clicking the fake CAPTCHA, the user is instructed to open the Terminal and paste a command. That command is not a verification step: it is a hidden installation script that downloads and executes the malware on the computer.

Once the command is run, the system connects to a remote server controlled by the attacker, from which Infiniti Stealer is silently downloaded and installed – with no pop-ups or warnings. Researchers point out that the malware is compiled as a native macOS binary, making it significantly harder to analyze and detect compared to a simple Python script. The malicious software is designed to steal crypto wallet data, credentials from browsers and the macOS Keychain, plaintext secrets from developer files, and screenshots captured during execution. It also checks whether it is running in an analysis environment to evade detection, sends the stolen data to the attacker’s server, and notifies the attacker via Telegram upon completion of the extraction.

The data confirms a worrying trend in personal wallet security. According to a report by blockchain security firm Chainalysis, $3.4 billion was stolen from the cryptocurrency industry in 2025. The most significant figure relates to the growth of attacks targeting personal wallets: their share of total stolen value rose from 7.3% in 2022 to 44% in 2024. Without the anomalous impact of the Bybit attack, this percentage would have reached 37% in 2025 as well.

Crypto users are advised to never paste commands into the Terminal from untrusted sources and to exercise maximum caution while browsing.

Previous Post

Canada: crypto political donations ban proposed

Next Post

Bitdeer: agreement in Norway for the country’s largest AI data center

Latest News

Trezor: vulnerabilità hardware nel secure element TROPIC01 del Safe 7, fondi al sicuro
Bitcoin

Trezor: hardware vulnerability in the TROPIC01 secure element of the Safe 7, funds remain safe

by Newsroom
June 3, 2026
0

An audit by the Ledger Donjon team identified a flaw in the Secure Element chip of the Trezor Safe 7...

Read moreDetails
USA: Treasury sanziona Nobitex, il più grande exchange di criptovalute iraniano
Bitcoin

USA: Treasury sanctions Nobitex, Iran’s largest crypto exchange

by Newsroom
June 3, 2026
0

The U.S. Department of the Treasury has designated Nobitex and three individuals for alleged ties to the Revolutionary Guards and...

Read moreDetails
Twenty One Capital: Tether propone fusione a tre con Strike ed Elektron Energy
Bitcoin

Twenty One Capital: four days to comply with NYSE rules

by Newsroom
June 2, 2026
0

The bitcoin treasury company controlled by Tether risks a "Below Compliance" flag from the New York Stock Exchange by Friday,...

Read moreDetails
Bitcoin: miner casalingo trova un blocco con una macchina da 300$
Bitcoin

Bitcoin: home miner finds a block with a $300 machine

by Newsroom
June 1, 2026
0

A home miner found block 951771 with a Canaan Avalon Nano 3S at 6.68 TH/s, beating odds of 1 in...

Read moreDetails
DOJ: sequestro record di 127.271 BTC legato a scam compound
Bitcoin

DOJ: record seizure of 127,271 BTC linked to scam compound

by Newsroom
June 1, 2026
0

The U.S. Department of Justice has brought renewed attention to the largest bitcoin confiscation case in history, tied to crypto...

Read moreDetails
Atlas21

© 2026 Atlas21

Navigate Site

  • Editorial Policy
  • Cookie Policy
  • Privacy Policy
  • Team

Follow Us

No Result
View All Result
  • Bitcoin 101
    • What Is Bitcoin? A Complete Guide
    • Bitcoin Security: A Complete Guide
    • Bitcoin Privacy: A Complete Guide
    • Lightning Network: A Complete Guide
    • Bitcoin Mining: A Complete Guide
    • Advanced Bitcoin: A Technical Guide
  • Learn
  • Latest News
  • Interviews
  • Opinion
  • Feature
  • B2B Services
  • About Us
  • Contacts

© 2026 Atlas21

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site, we will assume that you are happy with it.