'ClickLock' Malware Coerces Mac Users Into Giving Up Passwords

14 hours ago 2
Security steadfast Group-IB has identified a caller portion of macOS malware successful the chaotic that pressures users into surrendering their passwords via a barrage of fake strategy prompts.


Dubbed "ClickLock Stealer," the malware needs nary exploits and nary elevated privileges to work. Instead, the onslaught depends connected the unfortunate pasting a bid into Terminal and moving it. The bid past executes a script, and everything other follows.

Group-IB did not straight observe however victims are lured into pasting the command, but based connected the script's behavior, the steadfast believes it's served done a fake "ClickFix" leafage posing arsenic a Cloudflare cheque oregon browser verification step. Such pages instruct visitors to transcript a bid and tally it successful Terminal arsenic a expected "verification requirement."

Once it's up and running, the publication discreetly downloads respective modules and shows a terminal-based loading animation mimicking a Cloudflare advancement barroom with browser verification. If a idiosyncratic declines the archetypal password dialog that appears, the malware starts locking strategy usage.

Specifically, the malware kills each disposable app each 210 milliseconds portion the password punctual remains connected screen, and the remainder of the desktop stays unusable until the unfortunate gives in. Meanwhile, different loop suppresses macOS information notifications for astir six hours.

If the idiosyncratic gives up and enters their password, a second, genuine macOS punctual is subsequently forced to the front, asking them to let entree to a Keychain item. Granting it hands implicit Chrome's "Safe Storage" AES key, which is what the browser uses to encrypt saved passwords and cookies.

With the login password and Chrome's encryption obtained, ClickLock past harvests browser credentials, Keychain data, password manager vaults, and immoderate cryptocurrency wallets, and past sends it each to a Telegram bot. It besides installs a hidden backdoor disguised arsenic an iCloud process to springiness it continual access.

Group-IB says the run has been progressive since May 2026 and has targeted astatine slightest 100 victims crossed 33 countries. More than fractional of the victims were successful Europe.

Apple has already updated macOS to effort to support against this people of onslaught earlier it tin get underway. In macOS Tahoe 26.4, it added a warning that appears erstwhile the idiosyncratic attempts to paste a bid into Terminal from a website, chat, oregon message, and blocks the paste until the idiosyncratic reviews it. (Opera browser besides precocious added a akin feature.)

In cases wherever macOS detects known malware, the paste is blocked outright with nary override. Still, it should spell without saying that nary morganatic website volition ever inquire a idiosyncratic to paste a bid into Terminal.
This article, "'ClickLock' Malware Coerces Mac Users Into Giving Up Passwords" archetypal appeared connected MacRumors.com

Discuss this article successful our forums

Read Entire Article