• Home
  • Solutions
    • Managed Solutions
    • Consulting Services
    • Online Solutions
  • About
  • Contact

Welcome

Get Engaged
System Pro IT ManagementSystem Pro IT Management
System Pro IT ManagementSystem Pro IT Management
  • Home
  • Solutions
    • Managed Services

      Managed Business IT Support
      Managed Network & Cyber Security
      Managed Data Security and Backup
      Managed Systems Integrations
      Managed Voice & Conferences

      Read More
    • Consulting Services

      IT Infrastructure Design and Planning
      IT Expansion and Upgrade Planning
      Office Relocation Planning
      Business Continuity Planning
      Computerisation & Integration Consulting

      Read More
    • Online and Cloud Solutions

      Cloud Computing
      Corporate Presence Web Design
      eCommerce Design and Development
      Tailored Applications for Desktop & Mobile
      and more…

      Read More
  • About
  • Contact

Apple Mac User Alert: ClickLock Stealer

Apple Mac User Alert: ClickLock Stealer

20 July 2026 Posted by Andrew C Uncategorized

Cybersecurity firm Group-IB has warned that a new macOS modular info-stealing Trojan named “ClickLock Stealer” is spreading globally, affecting 33 countries across Europe, North America, and the Middle East, with at least over a thousand victims reported so far. The trojan employs system traps and extreme coercive measures: if the victim refuses to enter their Mac system login password, the malware triggers a destructive “Kill Loop” system kernel process, forcing the victim to surrender their password while being unable to operate their computer.

According to Group-IB’s investigation, ClickLock Stealer uses a malicious web-deception technique called “ClickFix.” Attackers leverage compromised WordPress sites, search engine poisoning (SEO Poisoning), or social media posts to redirect victims to counterfeit web pages.

The fraudulent webpage disguises itself as a “Cloudflare bot verification” or a verification-failure error message, instructing users to copy a specific command and paste it into macOS’s Terminal for execution. Since the command is manually executed by the user, the malware does not need to exploit any operating system zero-day vulnerabilities or escalate privileges—it directly gains user-level permissions and downloads subsequent modular scripts.

Once the user executes the command, a highly realistic Cloudflare verification animation appears in the Terminal window (e.g., prompts like “Verifying you are not a robot”), but in the background, four malicious modules are already downloaded from the compromised website, comprehensively scanning and exfiltrating sensitive system data.

Researchers state that to obtain the highly valuable macOS Keychain and Google Chrome’s Safe Storage encryption key, ClickLock Stealer displays a fake system password prompt box crafted via AppleScript.

If the user becomes suspicious and clicks “Cancel” or refuses to enter the password, the malware immediately installs two LaunchAgents in the system to ensure automatic execution upon the next boot login, then triggers the coercion mechanism. The malware terminates critical system processes at a rate of once every 210 milliseconds, frantically shutting them down.

This causes the user’s desktop to enter a near-paralysed frozen state, with only an irremovable password prompt box remaining on the screen. Once the victim compromises and enters the correct password due to being unable to use the computer, the malware gains full system control.

Moreover, ClickLock Stealer is highly targeted, capable of stealing credentials from eight web browsers, browser extensions for 31 cryptocurrency wallets, seven password management software, eight desktop cryptocurrency wallet applications, and more.

All this data is then transmitted via API to a Telegram bot server controlled by the attackers. After transmission is complete, the malware automatically modifies file timestamps and self-deletes to cover its tracks. However, it leaves behind an open-source reverse shell tool named “GSocket” in the system, disguising it as an iCloud-related process to establish a permanent backdoor on the victim’s computer.

Group-IB warns: never copy and paste unknown commands into Terminal—no legitimate website would ask users to do so, and it is “100% suspicious.” If you unfortunately fall victim and experience frequent automatic app closures or a frozen screen, absolutely do not enter any password into the pop-up window; immediately boot into Safe Mode and reset your system.

Share
0

About Andrew C

This author hasn't written their bio yet.
Andrew C has contributed 1 entries to our website, so far.View entries by Andrew C

Get in touch to engage with System Pro IT Management. Contact Us

Quick Contacts

  • PO Box 8282 Baulkham Hills NSW 2153
  • 02 8005 4043
  • info@systempro.com.au
  • https://systempro.com.au

Customer Services

  • Home
  • About
  • Contact

Copyright © 2026 — System Pro IT Management. All Rights Reserved.