TGViewer
Group-IB Group-IB @group_ib · 2.53K subscribers
Post #975 1.01K
🚨Group-IB researchers have uncovered ClickLock Stealer, a previously undocumented macOS malware that combines ClickFix social engineering, credential theft, crypto wallet harvesting, Keychain extraction, and persistent remote access into a single attack chain.

Key findings:
🔹At least 100 victims identified across 33 countries, with more than 50% located in Europe
🔹Targets 8 browsers, 31 crypto wallet extensions, 7 password manager extensions, and 8 desktop wallet applications
🔹Uses coercive "locker" techniques that repeatedly kill user applications until victims enter passwords or approve Keychain access
🔹Leverages Telegram bots for exfiltration and a modified GSocket backdoor for persistent access
🔹Relies entirely on social engineering, requiring no exploits or elevated privileges to compromise systems
🔹Had zero detections at the time of discovery

Read the full technical analysis.

#ThreatIntelligence #MalwareAnalysis #CyberSecurity #ClickLockStealer
  • 🔥 9
  • ❤ 5
  • 👍 4
  • 🏆 1
More from @group_ib
  1. Sep 23, 2026🚨Group-IB researchers have uncovered RemControl, a previously undocumented Android bankin…
  2. Sep 17, 2026🚨Group-IB Threat Intelligence has uncovered 29 new samples linked to the HEAVYGRAM and CR…
  3. Sep 14, 2026🚨 Inside the Smishing Triad’s Phishing Cockpit Group-IB’s latest research dives into JWR,…
  4. Sep 9, 2026🚨 Group-IB uncovers Vwork, a weaponized fork of the open-source Android app cloner Shelte…
  5. Sep 3, 2026🚨 Outsider Phishing Kit: a resilient PhaaS threat Group-IB researchers uncovered the Outs…
  6. Sep 1, 2026🚨 Cybercrime is evolving, and so is the underground economy behind it. Group-IB has uncov…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →