New macOS “ClickLock Stealer” Locks Macs Until Password Is Handed Over
What Happened — A modular macOS infostealer dubbed ClickLock Stealer, discovered by Group‑IB, is delivered through “ClickFix”‑style phishing pages. The malware forces victims to enter their macOS password by repeatedly killing core UI processes, steals browser, password‑manager and cryptocurrency‑wallet data, and leaves a persistent GSocket backdoor for ongoing remote access.
Why It Matters for Compliance & Audit Readiness
- Demonstrates a breakdown in logical‑access controls – attackers obtain privileged credentials and retain persistent access, a direct violation of SOC 2 CC6.1 (Logical Access).
- Underscores the importance of documented security‑awareness training and phishing‑simulation evidence to satisfy SOC 2 CC7.1 (Security Awareness).
- Provides a concrete incident that can be logged as audit evidence for continuous monitoring of endpoint protection and privileged‑access management.
Who Is Affected — Organizations with macOS workstations across technology, professional services, finance, education, and other sectors.
Recommended Actions — Review and tighten macOS privileged‑access policies; enforce MFA for local admin accounts; deploy EDR with behavior‑based detection for process‑kill loops; conduct regular phishing‑awareness training and simulate similar attacks; capture and retain logs of credential use for SOC 2 audit trails. Source: Malwarebytes Labs
Technical Notes — Delivered via a malicious shell script masquerading as a Cloudflare verification page; shows a fake macOS password prompt with the victim’s real username and Apple icon; lockout achieved by terminating Finder, Dock, Terminal, Activity Monitor, Console, System Settings, Spotlight, and major browsers every 210 ms for up to 83 hours; exfiltrates data to a Telegram channel; persists through an open‑source GSocket backdoor. Source: Malwarebytes Labs