New 'ClickLock' Malware Targets Mac Users, Coercing Password Disclosure
Security firm Group-IB has identified a new macOS malware named 'ClickLock Stealer' that pressures users into revealing their passwords through fake system prompts. This malware does not require any exploits or elevated privileges to operate. Instead, it relies on users pasting a command into Terminal, which then executes a script. The script is believed to be distributed via a fake 'ClickFix' page that masquerades as a Cloudflare check or browser verification step, instructing users to run a command in Terminal. Once activated, the malware downloads several modules and displays a terminal-based loading animation mimicking a Cloudflare progress bar. If users decline the initial password prompt, the malware disrupts system usage by closing visible apps every 210 milliseconds, rendering the desktop unusable until the password is entered. Upon obtaining the password, a genuine macOS prompt appears, requesting access to a Keychain item, which, if granted, allows the malware to harvest browser credentials, Keyc...