August 24, 2026
Atlas21
ITA
podcast
news interviews learn feature industry opinion
Atlas21 B2B

Menu

Main categories

news interviews learn feature industry opinion

Secondary destinations

podcast Atlas21 B2B

Search Atlas21

Atlas21
  • ‎
No Result
View All Result
Atlas21
No Result
View All Result
Atlas21
Home Bitcoin

macOS: fake CAPTCHA pages install malware to steal crypto

Newsroom by Newsroom
March 30, 2026
in Bitcoin
macOS: falsi CAPTCHA installano malware per rubare criptovalute
Share on FacebookShare on TwitterShare on Linkedin

A new infostealer called Infiniti Stealer targets Mac users through fake CAPTCHA pages that trick victims into running dangerous commands in the Terminal.

Security researchers at Malwarebytes have identified a new malicious campaign targeting crypto users on macOS. The attack exploits fake CAPTCHA pages that mimic the Cloudflare verification system to trick victims into installing an infostealer called Infiniti Stealer, designed to steal crypto wallet data, credentials, and other sensitive information from Apple computers.

The attack falls under the ClickFix category – a social engineering technique in which the user is manipulated into executing the malicious command themselves. The process begins with a fake page hosted on update-check[.]com, which faithfully replicates the appearance of a Cloudflare verification screen. After clicking the fake CAPTCHA, the user is instructed to open the Terminal and paste a command. That command is not a verification step: it is a hidden installation script that downloads and executes the malware on the computer.

Once the command is run, the system connects to a remote server controlled by the attacker, from which Infiniti Stealer is silently downloaded and installed – with no pop-ups or warnings. Researchers point out that the malware is compiled as a native macOS binary, making it significantly harder to analyze and detect compared to a simple Python script. The malicious software is designed to steal crypto wallet data, credentials from browsers and the macOS Keychain, plaintext secrets from developer files, and screenshots captured during execution. It also checks whether it is running in an analysis environment to evade detection, sends the stolen data to the attacker’s server, and notifies the attacker via Telegram upon completion of the extraction.

The data confirms a worrying trend in personal wallet security. According to a report by blockchain security firm Chainalysis, $3.4 billion was stolen from the cryptocurrency industry in 2025. The most significant figure relates to the growth of attacks targeting personal wallets: their share of total stolen value rose from 7.3% in 2022 to 44% in 2024. Without the anomalous impact of the Bybit attack, this percentage would have reached 37% in 2025 as well.

Crypto users are advised to never paste commands into the Terminal from untrusted sources and to exercise maximum caution while browsing.

Previous Post

Canada: crypto political donations ban proposed

Next Post

Bitdeer: agreement in Norway for the country’s largest AI data center

Latest News

HIVE firma un contratto AI da 350 milioni di dollari
Bitcoin

HIVE signs $350 million AI contract

by Newsroom
August 21, 2026
0

The agreement requires a buildout of about $185 million, scheduled for the fourth quarter of 2026.

Read moreDetails
Presentato disegno di legge per una riserva strategica di Bitcoin in New Hampshire e North Dakota
Industry

US debt surpasses $40.049 trillion

by Newsroom
August 20, 2026
0

Trump says he will listen to advisers on Bitcoin accumulation

Read moreDetails
Bitcoin

Phishing against 885,000 phone numbers to steal cryptocurrencies

by Newsroom
August 20, 2026
0

Operation Asterix used fake wallet sites and apps to steal seed phrases

Read moreDetails
HMRC invia oltre 81.000 lettere ai possessori di digital asset
Industry

HMRC sends over 81,000 letters to digital asset holders

by Newsroom
August 20, 2026
0

The notices concern the 2025/2026 tax year

Read moreDetails
Abstract representation of a futuristic digital processor with glowing elements.
Bitcoin

Blockstream tests post-quantum signatures on four wallets

by Newsroom
August 20, 2026
0

The research measured five hash-based schemes on Jade, Trezor, Ledger and BitBox02

Read moreDetails
Atlas21

© 2026 Atlas21

Navigate Site

  • Editorial Policy
  • Cookie Policy
  • Privacy Policy
  • Team
  • Podcast
  • Home redesign preview

Follow Us

Atlas21
News Interviews Learn Feature Industry Opinion Podcast Atlas21 B2B

Social

X Instagram Nostr LinkedIn YouTube

Contact us

[email protected] Privacy Cookie

The rabbit hole has no bottom.

© 2026 Atlas21. All rights reserved.

No Result
View All Result
  • Bitcoin 101
    • What Is Bitcoin? A Complete Guide
    • Bitcoin Security: A Complete Guide
    • Bitcoin Privacy: A Complete Guide
    • Lightning Network: A Complete Guide
    • Bitcoin Mining: A Complete Guide
    • Advanced Bitcoin: A Technical Guide
  • Learn
  • Latest News
  • Interviews
  • Opinion
  • Feature
  • Podcast
  • B2B Services
  • About Us
  • Contacts

© 2026 Atlas21

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site, we will assume that you are happy with it.