New ClickLock Malware Targets macOS Users, Forcing Password Disclosure
A new malware named ClickLock has been identified targeting macOS users by forcing them to reveal their system login passwords. The malware operates by terminating all visible processes, creating a scenario where users are compelled to enter their login credentials. ClickLock is designed to steal a variety of sensitive information, including cryptocurrency assets, login credentials, password-manager data, and browser information. It can also install a persistent backdoor for ongoing remote access. Researchers from Group-IB discovered the malware on VirusTotal, noting that it had infected at least 100 systems across 33 countries since May. The malware uses social engineering tactics, such as a fake Cloudflare 'human verification' sequence, to trick users into entering their passwords. Once the password is entered, the information is exfiltrated to the attacker via Telegram.