ClickLock Mac Malware Traps Users in a Three-Day Password Loop
ID: e4b6e7dc-77ed-5ea2-8e00-8b73ce434e15
STIX ID: report--e4b6e7dc-77ed-5ea2-8e00-8b73ce434e15
Feed Name: TechRepublic Security
Group-IB uncovered ClickLock, a macOS stealer that lures victims to paste Terminal commands and displays a fake macOS password prompt; dismissing the prompt triggers persistent LaunchAgents that force-close system apps and browsers hundreds of times per minute and can run for days, while the malware exfiltrates saved credentials, session cookies, password manager and wallet data and leaves a GSocket-like backdoor for continued access. The operation has targeted at least 100 people in 33 countries (many in Europe) and appears to focus on cryptocurrency holders; researchers advise disconnecting infected machines, restarting in Safe Mode, and resetting credentials from a trusted device.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
