Automatically translated.View original post

New threat macOS malware ClickLock Stealer

New perils macOS Malware ClickLock Stealer at Just Paste, Data Stealable

According to a report by the official website of the developer of the famous anti-malware tool Malwarebytes, Malwarebytes has mentioned the detection of a malware type that steals data from the victim's system or a new Infostealer called ClickLock Stealer that specifically focuses on attacks on users of the macOS operating system. This malware was detected by a research team from Group-IB, a cybersecurity specialist from Singapore. The research team found that hackers would start by deceiving the victim by phishing the victim into a fake website. The fake website takes the victim to a fake Verification screen, tricking the victim into opening the Terminal application and placing the code on it. Screen This is a method called ClickFix that tricks the victim into following commands to download and install malware on the machine manually. In addition to installing malware theft, the system's back-door or backdoor malware is installed, called GSocket, to facilitate hackers to access the system at any time.

After the victim has installed the malware on the victim's machine, the malware will bounce up a fake screen to trick the victim into filling in the system password by force. If the victim refuses to enter the password, the malware will shut down key functions on the system, such as Finder, Dock, Terminal, Activity Monitor, Console, System Settings, Spotlight, and web browsers, until the victim has entered the password. The key shutdown will loop every 210 seconds to 83 hours until the victim completes the correct password. If the victim completes the requested password, the system will activate it, but behind the malware, it will send the password, as well as other information previously stolen by the malware, back to hackers on the control server (C2 or Command and Control) located on the famous chat service Telegram for verification and further use.

After the malware has finished stealing the data, the malware will delete itself to evade detection, but the GSocket malware will not be deleted to allow hackers to resume data theft by reinstalling the same malware or secretly installing other malware on the system to deal with the hacker's indulgent machine.

# Trending # lemon 8 diary # macos # freedomhack # Malware

8/4 Edited to

... Read moreประสบการณ์การใช้งานระบบ macOS ในชีวิตประจำวันทำให้ผมเห็นความสำคัญของการรักษาความปลอดภัยข้อมูลส่วนตัวอย่างมาก ในช่วงหลังมานี้ มีข่าวมัลแวร์ใหม่ชื่อ ClickLock Stealer ที่สามารถขโมยข้อมูลได้เพียงแค่ผู้ใช้กด Paste ทำให้ผมเริ่มตระหนักว่าแค่การใช้งานพื้นฐานทั่วไปก็สามารถตกเป็นเหยื่อได้โดยไม่รู้ตัว มัลแวร์นี้มักเริ่มด้วยการส่งลิงก์หลอกให้ผู้ใช้เข้าเว็บไซต์ปลอมผ่านวิธีการ Phishing โดยผู้ใช้จะถูกชักชวนให้เปิด Terminal ใน macOS และรันโค้ดที่ดูเหมือนจะเป็นขั้นตอนยืนยันตัวตน เมื่อโค้ดนี้ถูกรัน เครื่องจะติดตั้งมัลแวร์ ClickLock Stealer พร้อมกับมัลแวร์ backdoor ที่ชื่อ GSocket เพื่อให้แฮกเกอร์สามารถเข้าถึงเครื่องได้ตลอดเวลา สิ่งที่น่ากลัวที่สุดคือหลังติดตั้งมัลแวร์นี้ จะขึ้นหน้าจอปลอมบังคับให้ผู้ใช้กรอกรหัสผ่านระบบ หากผู้ใช้ไม่กรอก มัลแวร์จะปิดฟังก์ชันสำคัญของ macOS เช่น Finder, Dock, Terminal และเว็บเบราว์เซอร์ต่างๆ หมุนวนเป็นลูปทำให้เครื่องใช้งานไม่ได้ ทำให้ต้องยอมกรอกรหัสผ่านไปโดยปริยาย และรหัสผ่านพร้อมข้อมูลอื่นๆ ที่ถูกขโมยจะถูกส่งกลับไปยังเซิร์ฟเวอร์ควบคุมบน Telegram จากประสบการณ์ส่วนตัว ผมแนะนำให้ผู้ใช้ macOS ทุกคนตั้งค่าความปลอดภัยด้วยการเปิดใช้ไฟร์วอลล์ และระบบป้องกันมัลแวร์ที่อัปเดตเสมอ รวมถึงไม่ควรเปิดลิงก์ หรือไฟล์ที่มาจากแหล่งที่ไม่น่าเชื่อถือและไม่พิมพ์คำสั่งใดๆ ที่ได้รับจากคนแปลกหน้าใน Terminal เพราะอาจติดกับดักมัลแวร์ได้ง่าย นอกจากนี้ การสำรองข้อมูล (Backup) อย่างสม่ำเสมอก็เป็นอีกแนวทางหนึ่งที่ช่วยลดความเสียหายในกรณีเครื่องถูกโจมตีได้มากเช่นกัน ผมเองก็เคยเจอสถานการณ์คล้ายๆ กันมาแล้ว ความรู้และการระมัดระวังเป็นเกราะป้องกันที่ดีที่ช่วยรักษาข้อมูลสำคัญให้ปลอดภัยจากภัยคุกคามไซเบอร์ในยุคนี้ได้อย่างมีประสิทธิภาพ