New ClickLock macOS Malware Forces Users to Surrender Login Passwords

A new macOS malware strain called ClickLock is actively targeting users by terminating all visible applications and trapping them into revealing their system login passwords. Discovered by Group-IB researchers on VirusTotal, the malware remains completely undetected by security vendors and has already compromised at least 100 systems across 33 countries since May. The attack typically begins through a ClickFix lure that tricks victims into running a malicious Terminal command disguised as a Cloudflare human verification check.

Once executed, ClickLock suppresses macOS notifications for roughly six hours and downloads its stealer modules in the background. The malware then displays a fake password dialog using the victim's real username and a downloaded Apple icon. If the user cancels the prompt, ClickLock establishes persistence through two LaunchAgents and reloads at the next login, at which point it aggressively kills core applications like Finder, Dock, Terminal, and web browsers every 210 milliseconds until the victim complies and enters their password.

The stolen credentials are exfiltrated to attackers via Telegram, enabling theft of cryptocurrency assets, password-manager data, browser information, and macOS authentication data. ClickLock also installs a persistent backdoor for ongoing remote access to compromised systems. What makes this threat particularly notable is that it requires no exploits or elevated privileges, relying entirely on social engineering and forced interaction to achieve its goals on fully patched macOS systems.

Read More at the original source →