ClickLock Stealer circumvents macOS protection features through aggressive process termination to force users to enter their passwords and then exfiltrate browsers, wallets and keychains.
ClickLock kills macOS applications in a continuous loop until users enter their password — a new extortion mechanism via LaunchAgents that requires systemic controls on…
PamStealer combines social engineering, native macOS functions, and Rust-based payloads to masquerade as a system process and steal passwords and clipboard contents.
A group active since 2023 distributes the macOS backdoor FlutterShell through Google-verified shell companies, which is signed with valid Apple IDs and can be remotely…
The JINX-0164 group compromises crypto developers through fake LinkedIn job interviews to deploy the Python malware AUDIOFIX, which steals passwords, SSH keys, and cryptocurrency wallet…