Modular macOS Stealer Uses Kill Loops to Force Password Entry
ID: 703b22d1-1d0a-580a-ab8c-a235dce5d223
STIX ID: report--703b22d1-1d0a-580a-ab8c-a235dce5d223
Feed Name: Infosecurity Magazine (News)
A newly observed macOS infostealer named ClickLock Stealer uses a paste-a-command lure and a coercion routine that makes the system unusable until the user provides their password; Group-IB links it to ~100 victims across 33 countries. The modular malware includes a Keychain stealer (extracting Chrome AES keys and cookies/passwords), an AppleScript-based fake password prompt validated against the local directory, a wallet-extension scraper targeting over 30 extensions, and a disguised GSocket reverse shell; it forces compliance with persistent LaunchAgents and process-kill loops, exfiltrates via Telegram, and removes most artifacts after execution. Users are advised not to paste Terminal commands from webpages and to boot into Safe Mode/force shutdown rather than enter passwords if coercive behavior occurs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
