logo

New ClickLock macOS Malware Traps Users Into Revealing Login Password

ID: 8dac98c4-c12a-5fd4-b1f9-adaf382a536d

STIX ID: report--8dac98c4-c12a-5fd4-b1f9-adaf382a536d

Feed Name: CosmicBytez Labs

Threat Score
80/100

Date Published: 2026-07-19

Date Updated: 2026-07-19

...
...

Security researchers disclosed ClickLock, a macOS information-stealer that lures victims with a fake Cloudflare verification page to run a shell command, then displays a fake password dialog and—if refused—enforces a 210 ms kill-loop for ~83 hours to coerce credentials; stolen data (browser credentials, crypto wallets, keychain, shell history, blockchain data) is ZIP-archived and exfiltrated via the Telegram Bot API, while a modified GSocket backdoor ensures long-term access. The campaign affected 100+ confirmed victims across 33 countries and was undetected by antivirus vendors at disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.