A brand new macOS information-stealing malware referred to as ClickLock terminates all seen processes and forces customers to enter their system login passwords.
The malware is designed to steal cryptocurrency belongings, login credentials, password supervisor information, browser data, macOS authentication information, and may also set up persistent backdoors for continued distant entry to contaminated methods.
Group-IB researchers analyzed the ClickLock shell script after discovering the malware in VirusTotal, which was first despatched on June ninth. On the time of reporting, this malware was not detected by all safety distributors obtainable on the platform.
Additional investigation revealed that the malicious script had contaminated a minimum of 100 methods in 33 nations since Could.
This breach doubtless begins by way of a ClickFix lure, as researchers noticed malicious instructions pasted into the terminal that triggered a faux Cloudflare “human verification” sequence with an animated progress bar.
On the identical time, keyboard interrupts are disabled, the terminal cursor is hidden, and stealer modules are downloaded within the background.
The macOS Notification Heart can be suppressed for about six hours, successfully disabling notifications that would expose the assault.

Supply: Group-IB
Drive password entry
Group-IB researchers emphasize that ClickLock doesn’t require exploits or privilege escalation, however fairly achieves its targets by social engineering and compelled interplay loops.
Profitable operations are achieved by the malware’s mechanism of forcing victims to enter their macOS system passwords.
Based on Group-IB, the script first shows a faux macOS password dialog utilizing the sufferer’s actual username and a downloaded Apple icon.
As soon as the consumer enters the password, the malware verifies the info and leaks it to the attacker by way of Telegram.
If the consumer cancels the dialog, the malware establishes persistence by two macOS LaunchAgents (com.authirity.plist, com.chromer.plist) and reloads on the subsequent login.
On the subsequent startup, the password stealing module executes an exit loop each 210 milliseconds concentrating on main apps (Finder, Dock, Terminal, Exercise Monitor, Console, System Settings, Highlight, Internet Browser, and so on.) and shows solely a password dialog on the display till the sufferer complies.
Group-IB stories that the loop is ready to final for 300,000 seconds (roughly 83 hours) or till the sufferer enters the right password.

Supply: Group-IB
The second LaunchAgent performs one other enforcement mechanism, additionally terminating most of the system purposes talked about above, requesting keychain authorization by way of a daily system immediate, and asking for authorization to entry Chrome’s Protected Storage key.
That key could possibly be used to decrypt offline passwords saved in Chromium, cookies, and autofill data from stolen databases.
This second mechanism has a repetition interval of 200 milliseconds and is configured to final roughly 35 days (3 million seconds).
ClickLock additionally deploys information assortment modules for:
- Knowledge from 8 browsers: Chrome, Firefox, Courageous, Edge, Opera, Vivaldi, Arc, Chromium
- Saved logins, cookies, autofill information, bookmarks, native storage, and session storage
- Cryptocurrency Pockets Extension and Desktop Pockets File
- Encrypted pockets vault supplies with chance of offline cracking
- password supervisor extension information
- EVM, Bitcoin, Solana, TRON, TON, Cryptocurrency Addresses Cached Throughout the Stack
- shell historical past
- FileZilla FTP configuration and up to date server information
- Fundamental system data and public IP deal with
The gathering module packages the collected data and abstract log information right into a ZIP archive and uploads them by way of the Telegram Bot API.
Information bigger than 40 MB are break up into smaller items, and retry logic resumes importing even after momentary community failures.
The ultimate module is a modified model of the open-source software GSocket, which acts as a persistent backdoor for attackers.
The backdoor establishes persistence by a number of strategies, together with modifying the LaunchAgent, crontab entries, and shell configuration information.
Connects by a GSocket relay and permits an attacker to open a reverse shell and take distant management of the system.
In contrast to different ClickLock modules, that are mechanically eliminated after execution, GSocket is the one element that persists on the contaminated system.

Supply: Group-IB
Group-IB warns that “the detection vary of the malware is slender” and that the malicious payload is hosted on compromised official and respected domains.
Moreover, this script has not been flagged as malicious by VirusTotal, and its modules are mechanically eliminated after execution, leaving no artifacts behind.
Nonetheless, researchers say that detection is feasible based mostly on actions generated by the malware, resembling launching password dialogs with osascript, repeatedly terminating processes, mass accessing the browser’s profile listing, and outbound connections to Telegram’s API.
To guard themselves from these assaults, customers ought to keep away from pasting terminal instructions that they don’t absolutely perceive, particularly if the request is from an internet site.
“Regardless of how skilled a web page that instructs you to open a terminal could also be, it’s trying to compromise your system,” the researchers wrote.
If you’re prompted for a login password when the remainder of the system seems unresponsive, Group-IB recommends holding down the ability button to power the system shutdown and booting into Protected Mode to get well the system.
Safety groups doc 54% of profitable assaults and situation a warning on solely 14%. The remaining strikes invisibly by the surroundings.
Picus’ whitepaper exhibits easy methods to take a look at your SIEM and EDR guidelines in breach and assault simulations to make sure threats go undetected.
Get the white paper
