Group-IB has identified a new macOS infostealer, ClickLock Stealer, that uses a coercive technique to force victims to enter their login password. The malware arrives as a command pasted into Terminal, displaying a fake system dialog. When the victim cancels, it installs two LaunchAgents and exits. Upon the next login, critical applications such as Finder, Dock, Spotlight, Terminal, Activity Monitor, and major browsers are killed every 210 milliseconds for up to 83 hours, leaving only a password box on the desktop. Once the password is entered, the malware exfiltrates Keychain data, browser credentials, and cryptocurrency wallets.
Group-IB’s telemetry indicates at least 100 targets across 33 countries since May 2026, with over half in Europe. The malware is believed to be under active development. The orchestrator script, uploaded to VirusTotal on June 9, had zero detections at the time of analysis. The attack chain includes compromised payload hosts, but the initial lure pages remain unconfirmed. A successful compromise provides the operator with the validated macOS login password, Chrome’s Safe Storage AES key, and a ZIP archive containing browser credentials, cookies, crypto wallet extension storage, desktop wallet files, password manager vaults, the Keychain, shell history, and FileZilla server credentials.
Group-IB advises victims to revoke active browser sessions, treat all saved passwords, cookies, and wallet keys as compromised, and change them immediately. The malware’s unique coercion loop, which kills apps at sub-second intervals, has no legitimate use case and is designed to force password entry. The backdoor component, goyim, is largely a copy of the GSocket open-source tunneling toolkit, using a relay for command and control. The stealer payloads are hosted on three compromised domains with clean reputations, and data exfiltration occurs via three Telegram bots.
Malware: ClickLock Stealer, goyim, GSocket, SHub Stealer, AMOS, MacSync
Companies: Group-IB, Apple, Microsoft, Jamf, Cloudflare, The Hacker's Choice, Google
Products: Chrome, FileZilla, Telegram, VirusTotal, macOS, Terminal, Finder, Dock, Spotlight, Activity Monitor, NotificationCenter, SystemUIServer
Original source: thehackernews.com