New ClickLock macOS Malware Traps Users Into Revealing Login Password
ID: 8dac98c4-c12a-5fd4-b1f9-adaf382a536d
STIX ID: report--8dac98c4-c12a-5fd4-b1f9-adaf382a536d
Feed Name: CosmicBytez Labs
Security researchers disclosed ClickLock, a macOS information-stealer that lures victims with a fake Cloudflare verification page to run a shell command, then displays a fake password dialog and—if refused—enforces a 210 ms kill-loop for ~83 hours to coerce credentials; stolen data (browser credentials, crypto wallets, keychain, shell history, blockchain data) is ZIP-archived and exfiltrated via the Telegram Bot API, while a modified GSocket backdoor ensures long-term access. The campaign affected 100+ confirmed victims across 33 countries and was undetected by antivirus vendors at disclosure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
