logo

ClickLock Mac Malware Traps Users in a Three-Day Password Loop

ID: e4b6e7dc-77ed-5ea2-8e00-8b73ce434e15

STIX ID: report--e4b6e7dc-77ed-5ea2-8e00-8b73ce434e15

Feed Name: TechRepublic Security

Threat Score
70/100

Date Published: 2026-07-17

Date Updated: 2026-07-18

Author: Liz Ticong

...
...

Group-IB uncovered ClickLock, a macOS stealer that lures victims to paste Terminal commands and displays a fake macOS password prompt; dismissing the prompt triggers persistent LaunchAgents that force-close system apps and browsers hundreds of times per minute and can run for days, while the malware exfiltrates saved credentials, session cookies, password manager and wallet data and leaves a GSocket-like backdoor for continued access. The operation has targeted at least 100 people in 33 countries (many in Europe) and appears to focus on cryptocurrency holders; researchers advise disconnecting infected machines, restarting in Safe Mode, and resetting credentials from a trusted device.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.