Malware

ClickLock macOS Malware

July 18, 2026 00:24 · 10 min read
ClickLock macOS Malware

A new macOS information-stealing malware, dubbed ClickLock, has been discovered by researchers at Group-IB. This malware terminates all visible processes, forcing users to enter their system login password, allowing it to steal sensitive information.

How ClickLock Malware Works

The ClickLock malware is designed to steal cryptocurrency assets, login credentials, password-manager data, browser information, and macOS authentication data. It can also install a persistent backdoor for ongoing remote access to infected systems.

Researchers analyzed the ClickLock shell script after discovering the malware on VirusTotal, where it was first submitted on June 9. At the time of the report, it remained undetected by all security vendors available on the platform.

Infection Vector

The compromise likely begins via a ClickFix lure, as the researchers observed pastes of a malicious command in the Terminal that trigger a fake Cloudflare “human verification” sequence with an animated progress bar.

At the same time, keyboard interrupts are disabled, the terminal cursor is hidden, and the stealer modules are downloaded in the background. The macOS NotificationCenter is also suppressed for about six hours, effectively disabling notifications that could expose the attack.

Forcing Password Entry

Group-IB researchers highlight that ClickLock does not require any exploits or elevated privileges but achieves its goal through social engineering and forced interaction loops. Operational success is obtained through the malware's mechanism for coercing the victims into entering their macOS system password.

The script initially displays a fake macOS password dialog using the victim’s real username and a downloaded Apple icon. If the user enters their password, the malware validates the data and exfiltrates it to the attacker via Telegram.

Persistence Mechanism

In case the user cancels the dialog, the malware establishes persistence via two macOS LaunchAgents (com.authirity.plist, com.chromer.plist) and reloads at the next login. At the next activation, the password-stealing module runs a termination loop every 210 milliseconds, targeting key apps and shows only a password dialog on the screen until the victim complies.

The loop is configured to continue for 300,000 seconds (about 83 hours), or until the victim supplies a correct password.

Data Harvesting Module

ClickLock also deploys a data-harvesting module, which targets the following: Data from eight browsers, saved logins, cookies, autofill data, bookmarks, local storage, and session storage. Cryptocurrency wallet extensions and desktop wallet files, encrypted wallet vault material for potential offline cracking, password-manager extension data, cached cryptocurrency addresses, shell histories, FileZilla FTP configuration and recent-server data, and basic system information and the public IP address.

The harvesting module packages the collected information and a summary log file into a ZIP archive, then uploads it via the Telegram Bot API. Files larger than 40 MB are split into smaller parts, while retry logic ensures that uploading resumes after temporary network failures.

Backdoor Module

The final module is a modified version of the open-source tool GSocket that acts as a persistent backdoor for the attackers. The backdoor establishes persistence through multiple methods, including a LaunchAgent, crontab entries, and modifications to shell configuration files.

It connects through a GSocket relay, allowing the attacker to open a reverse shell and remotely control the system. Unlike the other ClickLock modules that self-delete after execution, GSocket is the only component that persists on infected systems.

Detection and Prevention

Group-IB warns that the malware leaves a narrow detection window and that the malicious payloads are hosted on compromised legitimate domains with a clean reputation. Additionally, the script is not flagged as malicious on VirusTotal, and its modules self-delete after execution, leaving no artifacts.

However, detection is possible based on the activity generated by the malware, such as osascript launching password dialogs, repeated process termination, mass access to browser profile directories, and outbound connections to Telegram's API.

To defend against these attacks, users should avoid pasting in Terminal commands they don't fully understand, especially if the request comes from a website. If prompted to enter the login password when the rest of the system appears unresponsive, Group-IB recommends forcing a system shutdown by holding the power button and then booting into Safe Mode to recover the system.

Any page that instructs you to open Terminal, regardless of how professional it looks, is attempting to compromise your system.

Source: BleepingComputer

Source: BleepingComputer

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free