Overview
- Researchers say ClickLock has been active since at least May and Group‑IB reports it has hit roughly 100 targets across 33 countries.
- The attack begins with a ClickFix‑style page that tells users to copy and paste a command into Terminal, which downloads an orchestrator script and four payload modules.
- If a victim cancels a fake password prompt the malware installs LaunchAgents that run sub‑second process‑killing loops to terminate Finder, Dock, browsers and monitoring tools until the user types their macOS password.
- The campaign steals Keychain items including the Chrome Safe Storage AES key, browser credentials and cookies, password‑manager and crypto wallet data, then exfiltrates archives to Telegram bots and leaves a GSocket‑based backdoor for persistence.
- Group‑IB advises not to enter a password on an unresponsive desktop, to force shutdown and boot into Safe Mode for recovery, to revoke exposed credentials, and to hunt for LaunchAgent and Telegram API activity as indicators of compromise.