• 'macOS users may face real, sophisticated threats that require ne

    From TechnologyDaily@1337:1/100 to All on Friday, July 17, 2026 17:15:22
    'macOS users may face real, sophisticated threats that require neither exploits nor any elevated access to succeed': ClickLock Stealer tries to
    trick Apple users into revealing their passwords

    Date:
    Fri, 17 Jul 2026 16:05:00 +0000

    Description:
    ClickLock bores its victims into complying and then steals all sorts of data.

    FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter GroupIB uncovers ClickLock, a new macOSfocused infostealer using aggressive social engineering by spamming password prompts and terminating key apps every 210ms until victims comply Once credentials are obtained, it exfiltrates browser data, crypto wallets, password manager entries, FTP configs, and device info via Telegram Bot API Active since May 2026, spotted in 33 countries (mostly Europe), distributed via ClickFix campaigns, and initially undetected by security vendors until recently Security researchers from Group-IB have uncovered a new infostealer targeting primarily macOS users in Europe.

    Dubbed ClickLock , it is more of an annoying social engineering mechanism rather than a full-blown malware variant, constantly popping up a login
    prompt on the victims device, until they finally comply and share the credentials. Every 210 milliseconds it terminates key apps on the device (Finder, Dock, TErminal, etc.), essentially making it useless. At the same time, it keeps prompting a password dialog on the screen, making sure the victim can do nothing but provide the credentials. Latest Videos From Watch full video here: Targeting Europeans The loop is set to continue for more
    than three straight days, or until the victim folds.

    After getting the keys to the kingdom, the malware gets to work and starts exfiltrating valuable information. You may like Inside the relentless rise of the macOS AMOS infostealer This new macOS infostealer poses as an Apple crash reporting tool to try and steal all your valuable data Devious new
    infostealer Mac malware disguises itself as official Apple tools to lure in victims

    This includes data from key browsers (Chrome, Firefox, Brave, and others), saved logins, cookies, autofill data, and other browser information, data linked to cryptocurrency wallets and extensions, encrypted wallet vault material that can be cracked off-site, data from password managers , cached cryptocurrency addresses across EVM, Bitcoin, Solana, TRON, TON, and Stacks, shell histories, FileZilla FTP configuration and recent-server data, and
    basic device information.Everything is then packaged into a .ZIP archive and exfiltrated via a Telegram Bot API.

    Group-IB says the campaign has been active since at least May 2026, so its been active for a few months now. A researcher submitted a variant to VirusTotal in early June, but it remained undetected by all security vendors until recently, Group-IB says. Are you a pro? Subscribe to our newsletter
    Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me with news
    and offers from other Future brands Receive email from us on behalf of our trusted partners or sponsors By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.

    So far, it has been spotted in 33 countries, more than half of which are in Europe, it was also added. The malware is most likely being distributed via a ClickFix social engineering campaign, and has not been tied to any particular threat actor. The best antivirus for all budgets Our top picks, based on real-world testing and comparisons

    Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.



    ======================================================================
    Link to news story: https://www.techradar.com/pro/security/macos-users-may-face-real-sophisticated -threats-that-require-neither-exploits-nor-any-elevated-access-to-succeed-clic klock-stealer-tries-to-trick-apple-users-into-revealing-their-passwords


    --- Mystic BBS v1.12 A49 (Linux/64)
    * Origin: tqwNet Technology News (1337:1/100)