Stealers observed in the DriveSurge campaign (Silent Push: ClickFix + fake update driveby attacks on thousands of compromised sites). Two stage macOS malware with dedicated arm64 (Apple Silicon) and x86_64 (Intel) builds, obfuscated bash loader → ~30MB Garble Obfuscated Go stealer. Steals 100+ crypto wallets, macOS Keychain, browser creds/cookies, SSH/GPG keys. Patches Atomic Wallet & Exodus Electron apps to intercept passwords. Shows fake Ledger Live / Trezor Suite "security update" dialogs to phish 24-word seed phrases. Persistence via LaunchAgent + ~/.persistenced.
http://89.208.97.111:8133/api/t
http://45.155.71.15:8133/api/t
http://213.165.42.172:8133/api/t