ClickLock is a macOS information-stealing malware family that uses ClickFix-style social engineering and coercive on-host behavior to obtain a victim’s system password and steal sensitive data. The infection chain is associated with fake verification pages that persuade users to paste and execute a malicious command in Terminal. After execution, ClickLock downloads multiple components, suppresses visible signs of compromise, and presents a counterfeit Apple-style authentication prompt that incorporates the victim’s real username. Entered credentials are validated locally before exfiltration, ensuring that only correct passwords are sent to the operators.
If the victim refuses to provide the password, ClickLock establishes persistence through LaunchAgents and repeatedly terminates core macOS applications, including the desktop shell, system utilities, and web browsers, at very short intervals. This behavior can effectively lock the user out of normal interaction and leave the password prompt as the primary visible interface until credentials are entered. The malware also attempts to obtain access to Chrome Safe Storage and Keychain-related material, enabling decryption of protected browser data.
Once access is obtained, ClickLock steals browser passwords, cookies, autofill data, bookmarks, local and session storage, browser extension data, password manager data, cryptocurrency wallet data, shell history, FileZilla configuration data, and basic host information. Collected data is packaged into archives and exfiltrated through the Telegram Bot API, with support for splitting large files and resuming interrupted uploads. Many theft-oriented modules self-delete after execution to reduce forensic visibility.
ClickLock also deploys a modified GSocket-based backdoor that provides persistent reverse-shell access. This backdoor has been reported to persist through LaunchAgents, cron, and shell configuration changes while masquerading as benign macOS-related software. The malware relies on native macOS utilities and AppleScript rather than software exploits, emphasizing social engineering, credential theft, session theft, and defense evasion over privilege escalation. Observed targeting since May 2026 affected at least 100 systems across 33 countries, with more than half of known victims located in Europe. Cryptocurrency holders appear to be a notable focus, though the malware’s theft of browser and password-manager data also makes it relevant to enterprise users and other high-value macOS populations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
Этот компонент предоставляет атакующим реверс-шелл и закрепляется через LaunchAgent, cron и конфигурационные шелл-файлы.
Впервые управляющий шелл-скрипт этой малвари загрузили на VirusTotal 9 июня
ClickLock leverages AppleScript and native macOS utilities to carry out its operations, allowing it to blend into legitimate system activity and evade basic signature-based detection mechanisms.
Этот компонент предоставляет атакующим реверс-шелл и закрепляется через LaunchAgent, cron и конфигурационные шелл-файлы.
Если жертва закрывает окно, малварь создает два LaunchAgent — com.authirity.plist и com.chromer.plist.
Затем ClickLock показывает жертве фальшивое системное окно с настоящим именем пользователя и иконкой Apple, предлагая ввести пароль.
Остальные модули самостоятельно удаляются после выполнения, что помогает скрыть атаку.
After completing their tasks, data-stealing modules automatically delete themselves in order to reduce forensic evidence
a password prompt designed to harvest their credentials... it displays a false macOS password prompt... repeatedly launches until the correct password is entered. | it displays a false macOS password prompt based on the victim's actual username and an Apple-style interface in order to make it appear legitimate. After clicking the login button, ClickLock validates the credentials and immediately sends them to the attackers through Telegram.
passwords entered into the box are checked locally before anything is sent... a valid credential goes to the attackers.
После получения доступа стилер собирает в системе пароли, файлы cookie, данные автозаполнения и сессий из восьми браузеров
При этом вредонос запрашивает у жертвы доступ к Keychain, а также стремится получить ключ для Chrome Safe Storage.
ClickLock also deploys a data-harvesting module, which targets the following: Data from eight browsers... Cryptocurrency wallet extensions and desktop wallet files... Shell histories... FileZilla FTP configuration
a password prompt designed to harvest their credentials... it displays a false macOS password prompt... repeatedly launches until the correct password is entered. | it displays a false macOS password prompt based on the victim's actual username and an Apple-style interface in order to make it appear legitimate. After clicking the login button, ClickLock validates the credentials and immediately sends them to the attackers through Telegram.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as a recent Apple-user credential-theft threat for comparison/background.
Another malware family mentioned as part of a separate campaign targeting Apple devices; no further technical detail is provided in this content.
macOS infostealer that uses a ClickFix-style infection chain and fake system password prompt to coerce victims into entering their password. It kills key applications repeatedly to lock the user into the prompt, steals browser credentials, cookies, autofill and session data, crypto wallet data, password manager data, Keychain contents, shell history, and FileZilla settings, exfiltrating the data via Telegram Bot API. It also deploys a persistent reverse-shell backdoor component for continued access.
macOS information-stealing malware that uses social engineering to trick users into pasting malicious commands into Terminal, displays a fake macOS password prompt to harvest credentials, steals browser data, wallet files, Keychain-related data, shell histories, and system information, and installs persistence plus a backdoor for long-term access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.