The Go payload harvests browser-stored passwords, Apple iCloud Keychain data, and cached credentials from the infected system once executed . It also exfiltrates cookies, which can be used to hijack active web sessions
.
The malware's standout feature is a DRAIN function designed to siphon cryptocurrency assets from wallets on the infected Mac. It can empty wallets entirely, but it can also be configured to steal only a partial percentage of a wallet's balance, a deliberate tactic to avoid immediate detection by the victim . Huntress security researcher Andrew Brandt noted that "while the malware payload is capable of stealing passwords, its most interesting function is its capability to slowly deplete cryptocurrency accounts, siphoning their contents into accounts under the threat actor's control"
. The drainer targets multiple cryptocurrencies, including Bitcoin (BTC), Ethereum (ETH), Litecoin (LTC), Dogecoin (DOGE), and XRP (XRP)
. The malware also intercepts and redirects cryptocurrency transactions in real time
.
The malware establishes persistence on the infected system and can escalate privileges by generating a fake error via osascript that prompts the user for their administrator password . Huntress investigators traced the command-and-control infrastructure back to Aeza Group, a Russia-based bulletproof hosting provider that was sanctioned by the U.S. Treasury's OFAC in July 2025 for supporting cybercriminal operations
. The Treasury designation explicitly states Aeza Group played a role in supporting threat actors targeting victims in the United States and worldwide
. All components — the initial loader, payload hosting, and command-and-control server — tied back to infrastructure operated by Aeza Group
. The C2 link to a sanctioned provider is significant because it indicates the attackers deliberately chose infrastructure that is difficult to disrupt through traditional legal channels
.