🚨Group-IB researchers have uncovered ClickLock Stealer, a previously undocumented macOS malware that combines ClickFix social engineering, credential theft, crypto wallet harvesting, Keychain extraction, and persistent remote access into a single attack chain.
Key findings:
🔹At least 100 victims identified across 33 countries, with more than 50% located in Europe
🔹Targets 8 browsers, 31 crypto wallet extensions, 7 password manager extensions, and 8 desktop wallet applications
🔹Uses coercive "locker" techniques that repeatedly kill user applications until victims enter passwords or approve Keychain access
🔹Leverages Telegram bots for exfiltration and a modified GSocket backdoor for persistent access
🔹Relies entirely on social engineering, requiring no exploits or elevated privileges to compromise systems
🔹Had zero detections at the time of discovery
Read the full technical analysis.
#ThreatIntelligence #MalwareAnalysis #CyberSecurity #ClickLockStealer
Post #975
1.01K

- 🔥 9
- ❤ 5
- 👍 4
- 🏆 1