The record
Written from the 1 report below. Nothing here is unsourced.
- A new macOS infostealer called ClickLock is tricking users into pasting malicious commands into Terminal, disguised behind fake Cloudflare CAPTCHA pages.
- If the victim refuses to enter their password, the malware kills essential apps like Finder, Dock, and browsers every 210 milliseconds — for days — until the user complies.
- Once the password is given, it steals Keychain data, browser credentials, crypto wallets, and password manager vaults, and it manages to bypass recent Apple protections against malicious Terminal paste activity.
- Group-IB has tracked at least 100 victims across 33 countries since May, with over half in Europe.
What to watch next
- The malware's landing page design and distribution domains remain unidentified, so watch for updates on how victims are actually being lured in.
- Analysts believe the malware is still under development, so further refinements or new capabilities may emerge.
- Apple's Terminal paste mitigation has clear gaps, so watch for more campaigns exploiting similar workarounds.
Coverage1
1 report
English national1
All filed from India
Named European Union · Italy · Apple · macOS · ClickLock Stealer · Cloudflare · Group-IB · GSocket · Jamf Threat Labs · Microsoft · The Hacker's Choice
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
