HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

ClickLock Stealer Locks macOS Devices Until Victims Hand Over Their Passwords

ClickLock Stealer, a newly identified macOS infostealer, forces victims to enter their system password by killing core processes, exfiltrates browser and wallet data, and installs a persistent GSocket backdoor. The incident highlights gaps in access‑control policies and the need for robust security‑awareness training to meet SOC 2 audit requirements.

LiveThreat™ Intelligence · 📅 July 22, 2026· 📰 malwarebytes.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
4 sector(s)
Actions
4 recommended
📰
Source
malwarebytes.com

New macOS “ClickLock Stealer” Locks Macs Until Password Is Handed Over

What Happened — A modular macOS infostealer dubbed ClickLock Stealer, discovered by Group‑IB, is delivered through “ClickFix”‑style phishing pages. The malware forces victims to enter their macOS password by repeatedly killing core UI processes, steals browser, password‑manager and cryptocurrency‑wallet data, and leaves a persistent GSocket backdoor for ongoing remote access.

Why It Matters for Compliance & Audit Readiness

  • Demonstrates a breakdown in logical‑access controls – attackers obtain privileged credentials and retain persistent access, a direct violation of SOC 2 CC6.1 (Logical Access).
  • Underscores the importance of documented security‑awareness training and phishing‑simulation evidence to satisfy SOC 2 CC7.1 (Security Awareness).
  • Provides a concrete incident that can be logged as audit evidence for continuous monitoring of endpoint protection and privileged‑access management.

Who Is Affected — Organizations with macOS workstations across technology, professional services, finance, education, and other sectors.

Recommended Actions — Review and tighten macOS privileged‑access policies; enforce MFA for local admin accounts; deploy EDR with behavior‑based detection for process‑kill loops; conduct regular phishing‑awareness training and simulate similar attacks; capture and retain logs of credential use for SOC 2 audit trails. Source: Malwarebytes Labs

Technical Notes — Delivered via a malicious shell script masquerading as a Cloudflare verification page; shows a fake macOS password prompt with the victim’s real username and Apple icon; lockout achieved by terminating Finder, Dock, Terminal, Activity Monitor, Console, System Settings, Spotlight, and major browsers every 210 ms for up to 83 hours; exfiltrates data to a Telegram channel; persists through an open‑source GSocket backdoor. Source: Malwarebytes Labs

📰 Original Source
https://www.malwarebytes.com/blog/news/2026/07/new-clicklock-stealer-locks-your-mac-until-you-hand-over-your-password

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Could you prove your access controls held up here?

Credential and access failures map directly to SOC 2 access-control criteria. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →