Particle.news
Download on the App Store

ClickLock Stealer Locks Mac Desktops and Forces Users to Reveal Passwords

Researchers say the campaign uses a fake Cloudflare prompt and repeated app‑killing loops to coerce macOS users into handing over credentials, risking browsers, keychain and crypto wallets.

Overview

  • Group‑IB and other researchers found ClickLock uses a ClickFix-style lure that tells victims to paste a command into macOS Terminal which downloads an orchestrator script and payloads.
  • If a user cancels the fake password dialog the malware installs LaunchAgents and runs tight kill loops that terminate Finder, Dock, browsers and monitoring tools every ~210 milliseconds until the correct login password is entered.
  • When a valid password is obtained ClickLock harvests Keychain items, Chrome’s Safe Storage key, saved browser logins and cookies, password‑manager data, crypto wallet extensions and desktop wallet files and then packages the haul.
  • Stolen data and telemetry are sent over the Telegram Bot API and the attack leaves a lightweight GSocket‑derived reverse shell for persistent access while transient modules self‑delete to reduce traces.
  • Researchers reported the campaign in mid‑July 2026 and say it has hit roughly 100 victims across 33 countries; they advise powering off affected Macs, booting into Safe Mode, revoking credentials and never pasting Terminal commands from web pages.