Overview
- Group-IB published a detailed analysis on June 16 that links ClickLock to at least 100 compromised Macs in 33 countries and shows the campaign has been active since late May.
- The attack begins with a ClickFix-style page that instructs victims to paste a command into Terminal, which runs an orchestrator that downloads four payload components from compromised hosts.
- The orchestrator uses tight process-killing loops that repeatedly terminate Finder, Dock, browsers, Terminal, Activity Monitor and NotificationCenter so only a fake password dialog remains visible until the user types their login password.
- The malware chain is modular: a Keychain extractor queries Chrome’s Safe Storage key, a credential module validates and forwards real passwords, a crypto-wallet hunter pulls extension and wallet files, and a GSocket-based backdoor remains for persistence while stolen data is sent to Telegram bots.
- Researchers have not confirmed how victims were lured to the ClickFix pages and advise treating any site asking you to paste Terminal commands as hostile while urging force-shutdown and Safe Mode boot rather than entering credentials.