ClickLock Stealer is a modular macOS information stealer that uses ClickFix-style social engineering to trick victims into pasting and executing a command in Terminal. Rather than relying on exploits or elevated privileges, it abuses user-assisted execution and coercive interaction to obtain the victim’s macOS login password and approval for sensitive Keychain access. The malware has been observed targeting users across dozens of countries, with a strong concentration in Europe, and appears particularly focused on cryptocurrency holders and other users with valuable browser-stored secrets.
After execution, an orchestrator script presents a fake verification sequence while downloading multiple components. These modules harvest the macOS login password through a fake system dialog, validate the password locally, and steal the Chrome Safe Storage key from Keychain to enable offline decryption of Chromium-based browser cookies, saved passwords, and related data. Additional modules collect data from browsers, cryptocurrency wallet extensions, password manager extensions, desktop wallet applications, shell history, FTP credentials, blockchain addresses, and macOS Keychain material. Stolen data is exfiltrated through Telegram infrastructure rather than a conventional dedicated command-and-control server.
A defining feature of ClickLock Stealer is its coercive locker behavior. If the victim refuses to provide the requested password or approve Keychain access, the malware repeatedly kills visible applications in rapid loops, rendering the desktop largely unusable while leaving the credential prompt accessible. It also suppresses security notifications by repeatedly terminating notification-related processes for extended periods. For persistence, the malware can install LaunchAgents so the theft workflow resumes after login. Most theft components attempt to hinder forensic analysis through self-deletion and timestamp forgery, but the operation also installs a modified GSocket-based reverse-shell backdoor disguised as a benign macOS process, leaving a persistent foothold after the stealer modules finish. No confirmed threat actor attribution is established from the available information.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We have decided to name this malware ClickLock Stealer due to both ClickFix and “locker” techniques implemented in the attack, this way forming that distinctive chain.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
If they canceled, the orchestrator installed two LaunchAgents so both credential modules would be relaunched on the next login.
Execution started when the victim pasted a command into Terminal from what Group-IB assessed was a ClickFix page.
The page employs a ClickFix-style lure that instructs users to copy and paste a Base64-encoded command into the macOS Terminal app.
An orchestrator script hid the cursor and played a fake Cloudflare progress animation... The fourth installed GSocket ... disguised on macOS as an iCloud process.
Two modules focus on credential theft, one targeting macOS Keychain for Chrome passwords and another presenting a fake password dialog.
via a barrage of fake system prompts... If the user gives up and enters their password, a second, genuine macOS prompt is subsequently forced to the front, asking them to allow access to a Keychain item.
A Keychain stealer queried macOS for the Chrome Safe Storage key, the AES key that decrypts Chrome-stored cookies and passwords offline.
Two modules focus on credential theft, one targeting macOS Keychain for Chrome passwords and another presenting a fake password dialog.
Telegram gives operators encrypted transport that network filters rarely block.
16 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as another macOS stealer with similar password-theft behavior delivered via ClickFix-style phishing pages.
Another macOS stealer family mentioned for behavioral comparison, noted as using ClickFix-style phishing pages and similar password-capture behavior.
A newly documented macOS infostealer that uses social engineering via likely ClickFix phishing pages to trick users into pasting commands into Terminal. It steals passwords, Keychain data, browser and wallet data, password manager extensions, shell history, FTP credentials, and blockchain addresses; coerces victims by locking down the desktop with repeated process-kill loops until credentials are entered; exfiltrates data via Telegram bots and compromised domains; and leaves behind a modified GSocket reverse-shell backdoor for persistence.
macOS malware that tricks users into running a Terminal command, uses fake system prompts and app-killing behavior to coerce password entry, suppresses security notifications, steals browser credentials, Keychain data, password manager vaults, and cryptocurrency wallets, exfiltrates data via a Telegram bot, and installs a hidden backdoor disguised as an iCloud process for persistence.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.