Plan
archived
ClickLock macOS malware kills processes to steal login password
- Engineer — Learn: Novel macOS credential-harvesting technique worth understanding, but no KEV listing, PoC, or exploitation signals — no patch or config change required today. File for reference when evaluating EDR coverage on macOS developer endpoints.
- SOC/IR — Plan: The forced-process-termination-then-password-prompt pattern is a detectable behavior sequence on macOS EDR; add detection logic for mass process kill events followed by a system authentication dialog this quarter. No IOCs published yet to sweep for.
- Leader — Skip
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.