ClickLock Stealer: Paste Once, Lose Everything
ID: dd09c55f-dd41-5f29-adb3-88dfa940fbae
STIX ID: report--dd09c55f-dd41-5f29-adb3-88dfa940fbae
Feed Name: Group-IB Blog
## Executive summary Group-IB reports on 'ClickLock Stealer', a newly observed modular macOS infostealer that leverages ClickFix paste-based social engineering to coerce users into granting credentials and Keychain access, harvests browser/password manager/desktop wallet data (including Chrome Safe Storage key and multiple crypto wallet extensions), and installs a persistent GSocket-based backdoor; components exfiltrate data via Telegram and compromised WordPress domains, the operation targeted ~100 victims in 33 countries and employed anti-forensic timestomping and self-deletion to evade detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
