logo

Modular macOS Stealer Uses Kill Loops to Force Password Entry

ID: 703b22d1-1d0a-580a-ab8c-a235dce5d223

STIX ID: report--703b22d1-1d0a-580a-ab8c-a235dce5d223

Feed Name: Infosecurity Magazine (News)

Threat Score
75/100

Date Published: 2026-07-16

Date Updated: 2026-07-16

...
...

A newly observed macOS infostealer named ClickLock Stealer uses a paste-a-command lure and a coercion routine that makes the system unusable until the user provides their password; Group-IB links it to ~100 victims across 33 countries. The modular malware includes a Keychain stealer (extracting Chrome AES keys and cookies/passwords), an AppleScript-based fake password prompt validated against the local directory, a wallet-extension scraper targeting over 30 extensions, and a disguised GSocket reverse shell; it forces compliance with persistent LaunchAgents and process-kill loops, exfiltrates via Telegram, and removes most artifacts after execution. Users are advised not to paste Terminal commands from webpages and to boot into Safe Mode/force shutdown rather than enter passwords if coercive behavior occurs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.