logo

New ClickLock macOS malware traps users into revealing login password

ID: 00e0a8c5-23f7-5379-93f1-30b7c68d5811

STIX ID: report--00e0a8c5-23f7-5379-93f1-30b7c68d5811

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2026-07-16

Date Updated: 2026-07-16

Author: Bill Toulas

...
...

Group-IB analyzed ClickLock, a macOS infostealer that uses social-engineering lures (fake Cloudflare prompts and macOS password dialogs) and aggressive process-kill loops to force users to disclose their login password; it harvests browser and crypto wallet data, exfiltrates via Telegram, and can install a persistent GSocket backdoor, with at least ~100 infections across 33 countries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.