**New ClickLock Malware Traps macOS Users into Revealing Login Password**
A sophisticated piece of malware has been discovered targeting macOS users, with a particularly insidious tactic to force victims into revealing their system login password. Dubbed ClickLock, this information-stealing malware is designed to pilfer sensitive data, including cryptocurrency assets, login credentials, and browser information.
Researchers at Group-IB analyzed the malware after it was submitted to VirusTotal on June 9, where it remained undetected by all security vendors available on the platform at the time. Further investigation revealed that ClickLock has infected at least 100 systems across 33 countries since May, suggesting a significant and widespread threat.
The compromise typically begins with a lure called ClickFix, which presents a malicious command in the Terminal that triggers a fake Cloudflare “human verification” sequence with an animated progress bar. As the user interacts with this fake prompt, keyboard interrupts are disabled, and the terminal cursor is hidden. Meanwhile, stealer modules are downloaded in the background.
The most significant aspect of ClickLock’s operation is its ability to force victims into entering their macOS system password. The malware displays a fake macOS password dialog using the victim’s real username and a downloaded Apple icon. If the user enters their password, it is validated by the malware, which then exfiltrates the data to the attacker via Telegram.
If the user cancels the dialog, ClickLock establishes persistence via two macOS LaunchAgents (com.authirity.plist, com.chromer.plist) that reload at the next login. The password-stealing module then runs a termination loop every 210 milliseconds, targeting key apps and displaying only a password dialog on the screen until the victim complies.
Group-IB reports that this loop is configured to continue for 83 hours or until the user supplies a correct password. Additionally, ClickLock deploys a data-harvesting module that targets sensitive information from eight browsers, cryptocurrency wallet extensions, encrypted wallet vault material, and more.
The malware also packages collected information into a ZIP archive and uploads it via the Telegram Bot API. Files larger than 40 MB are split into smaller parts, while retry logic ensures that uploading resumes after temporary network failures.
In a concerning twist, ClickLock’s persistence mechanism involves installing a modified version of the open-source tool GSocket as a backdoor for attackers. This component persists on infected systems and allows remote control through a GSocket relay.
**Practical Takeaway**
ClickLock’s cunning tactics highlight the importance of caution when interacting with unfamiliar commands or prompts in the Terminal. It is essential to verify the authenticity of any prompt, especially those related to security or system configuration. Additionally, users should be aware that even a single misstep can lead to the compromise of sensitive data.
In this case, ClickLock’s persistence mechanism and ability to force victims into revealing their password demonstrate the need for robust cybersecurity measures on macOS systems. Users are advised to regularly update their operating system, security software, and browser extensions, as well as maintain strong passwords and enable two-factor authentication whenever possible.
Source: Bleeping Computer — 2026-07-16