ClickLock Stealer: macOS ClickFix Infostealer Uses 210ms Process-Kill Loops and Fake Authentication Dialogs to Coerce Credentials — Threadlinqs Intelligence
As of 2026-07-17, ClickLock Stealer: macOS ClickFix Infostealer Uses 210ms Process-Kill Loops and Fake Authentication Dialogs to Coerce Credentials is a high-severity malware threat attributed to ClickLock Dev, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 24 indicators of compromise.
Threat ID: TL-2026-1440 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: ClickLock Dev · FINANCIAL
ClickLock Stealer is a macOS infostealer, first identified by Group-IB, delivered via a ClickFix social-engineering lure that tricks victims into pasting a Terminal command disguised as a Cloudflare
ClickLock Stealer is a modular macOS credential- and cryptocurrency-stealing malware family discovered and named by Group-IB Threat Intelligence in July 2026, with the campaign active since at least May 2026 — roughly one month after macOS 26.4 introduced Terminal paste warnings, suggesting rapid attacker adaptation to platform defenses. The malware is distributed through the ClickFix technique: victims land on phishing pages spoofing a Cloudflare 'Verify you are human' challenge and are instructed to open Terminal and paste a supplied command, framed as a required browser-verification step. No CVE or software vulnerability is exploited; the entire chain relies on social engineering and abuse of legitimate macOS utilities (osascript, dscl, launchctl, security, curl|bash).
The initial payload, an orchestrator shell script (script.sh, SHA1 d9617710d4ed8e9b87f6fee0b7014c4101effba0), disables keyboard interrupts (trap on SIGINT), hides the Terminal cursor, and renders a fake animated Cloudflare CAPTCHA banner ('Verifying you are not a bot', 'Collecting browser signals') for roughly 10 seconds while it silently fetches four additional modules from two to three compromised, cleanly-reputed domains (including a hacked WordPress site) disguised with misleading extensions (.txt, .jpg, .css) — a classic curl-piped-to-bash pattern. The orchestrator itself performs an initial osascript-based password prompt: the harvested password is validated locally via `dscl /Local/Default -authonly` before exfiltration, so only working credentials are ever sent to the attacker.
If the victim dismisses or cancels the first prompt, two persistence/coercion LaunchAgents are installed: com.authirity.plist runs a kill loop every 210 milliseconds against Finder, Dock, Terminal, Activity Monitor, Console, System Settings, Spotlight, NotificationCenter, SystemUIServer, all major browsers, and shell processes (fish, zsh) for up to ~83 hours (300,000 seconds) or until the password is captured, rendering the desktop unusable except for the fake password dialog. com.chromer.plist runs a second loop at ~200-250ms intervals for up to ~35 days (34.7 days) requesting a legitimate macOS Keychain-authorization prompt to obtain Chrome's Safe Storage AES key, used to decrypt saved browser credentials and cookies offline. A separate background loop kills NotificationCenter continuously for ~6 hours specifically to suppress Gatekeeper and other security warnings that might tip off the victim. If Terminal lacks Full Disk Access, the malware proactively opens System Settings to the correct privacy pane and walks the victim through granting it.
Following credential capture, dedicated modules (chromer — Chrome Safe Storage key extraction; zsh/zoom — fake-dialog password harvesting; finderv2/finder.sh — cryptocurrency and wallet harvesting) systematically loot: 8 browsers (Chrome, Brave, Edge, Opera, Vivaldi, Arc, Chromium, Firefox) for saved logins, cookies, autofill, and bookmarks; 31 Chromium-based crypto wallet extensions (MetaMask, Phantom, Coinbase Wallet, Trust Wallet, Rabby, Rainbow, Exodus, Keplr, Solflare, OKX Wallet, Backpack, Yoroi, Tonkeeper, Xverse, UniSat, Ronin, TronLink, Zerion, MyTonWallet, Bitget, Leather, Bittensor, and others) and 7 Firefox equivalents (MetaMask, Phantom, Ronin Wallet, Alby, FilSnap, Tonkeeper, Solflare); 7 password-manager extensions (Bitwarden, LastPass, 1Password, iCloud Passwords, NordPass, Keeper, Dashlane); 8 desktop wallet applications (Exodus, Coinomi, Electrum, Atomic Wallet, Wasabi Wallet, Bitcoin Core, Feather/Monero, 1Password); cached blockchain addresses across 6 chains (EVM, Bitcoin, Solana, TRON, TON, Stacks); macOS Keychain databases; shell history (~/.zsh_history, ~/.bash_history); and FileZilla FTP credentials (sitemanager.xml, recentservers.xml), including encrypted {data, iv, salt} vault blobs pulled from Chromium LevelDB and Firefox IndexedDB stores.
All stolen data is exfiltrated to attacker-controlled Telegram bo
Target sectors: individuals, cryptocurrency, finance
Target regions: Europe, North America, Middle East, Africa
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 24 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1584, T1566, T1204.004, T1059.004, T1059.002, T1543.001, T1053.003, T1546.004, T1036.005, T1070.004