# ClickLock Dev

> As of 2026-07-17, ClickLock Dev is a threat actor tracked by Threadlinqs Intelligence across 2 threats spanning malware. ATT&CK coverage spans 79 techniques across 13 tactics in 2 of 2 tracked threats. Most-observed techniques: T1005 (Data from Local System), T1033 (System Owner/User Discovery), T1036.005 (Match Legitimate Resource Name or Location).

- **Tracked threats:** 2
- **Categories:** MALWARE
- **As of:** 2026-07-17

## ATT&CK techniques observed

79 techniques observed across 2 of 2 tracked threats. Tactics: Stealth (formerly Defense Evasion) (13), Credential Access (12), Command and Control (10), Discovery (9), Resource Development (8), Collection (7).

- [T1005](https://intel.threadlinqs.com/technique/T1005) Data from Local System — Collection — observed in 2 of 2 tracked threats
- [T1033](https://intel.threadlinqs.com/technique/T1033) System Owner/User Discovery — Discovery — observed in 2 of 2 tracked threats
- [T1036.005](https://intel.threadlinqs.com/technique/T1036.005) Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion) — observed in 2 of 2 tracked threats
- [T1056.002](https://intel.threadlinqs.com/technique/T1056.002) GUI Input Capture — Credential Access — observed in 2 of 2 tracked threats
- [T1057](https://intel.threadlinqs.com/technique/T1057) Process Discovery — Discovery — observed in 2 of 2 tracked threats
- [T1059.002](https://intel.threadlinqs.com/technique/T1059.002) AppleScript — Execution — observed in 2 of 2 tracked threats
- [T1059.004](https://intel.threadlinqs.com/technique/T1059.004) Unix Shell — Execution — observed in 2 of 2 tracked threats
- [T1070.004](https://intel.threadlinqs.com/technique/T1070.004) File Deletion — Stealth (formerly Defense Evasion) — observed in 2 of 2 tracked threats
- [T1070.006](https://intel.threadlinqs.com/technique/T1070.006) Timestomp — Stealth (formerly Defense Evasion) — observed in 2 of 2 tracked threats
- [T1071.001](https://intel.threadlinqs.com/technique/T1071.001) Web Protocols — Command and Control — observed in 2 of 2 tracked threats
- [T1082](https://intel.threadlinqs.com/technique/T1082) System Information Discovery — Discovery — observed in 2 of 2 tracked threats
- [T1083](https://intel.threadlinqs.com/technique/T1083) File and Directory Discovery — Discovery — observed in 2 of 2 tracked threats
- [T1187](https://intel.threadlinqs.com/technique/T1187) Forced Authentication — Credential Access — observed in 2 of 2 tracked threats
- [T1204.004](https://intel.threadlinqs.com/technique/T1204.004) Malicious Copy and Paste — Execution — observed in 2 of 2 tracked threats
- [T1489](https://intel.threadlinqs.com/technique/T1489) Service Stop — Impact — observed in 2 of 2 tracked threats

## Tracked threats

- [ClickLock Stealer: macOS ClickFix Infostealer Uses 210ms Process-Kill Loops and Fake Authentication Dialogs to Coerce Credentials](https://intel.threadlinqs.com/threat/TL-2026-1440) — HIGH
- [ClickLock Stealer: ClickFix-Delivered macOS Infostealer with GSocket Reverse-Shell Backdoor](https://intel.threadlinqs.com/threat/TL-2026-1402) — HIGH

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/ClickLock%20Dev
