A recent discovery by Group-IB has shed light on a new macOS stealer known as ClickLock Stealer. This malicious software has been targeting victims through a combination of social engineering tactics and coercion techniques, resulting in at least 100 victims across 33 countries in a span of two months, with a majority of the attacks occurring in Europe.
The ClickLock Stealer operates through a modular attack chain that begins when a victim unknowingly pastes a command into Terminal from a ClickFix webpage. This action triggers a series of events, including the download of four components from compromised WordPress sites. Two tools within the malware focus on stealing credentials, with one targeting the Chrome Safe Storage key and the other presenting a fake password dialog to extract passwords from the victim. Additionally, a module specifically hunts for cryptocurrency assets by targeting various wallet extensions and extracting encrypted vault fields from storage.
To ensure compliance from the victim, the ClickLock Stealer employs a coercion routine that forces the victim to surrender their password. If the victim initially enters their password, the operator receives it along with a system fingerprint. However, if the victim cancels, the malware installs LaunchAgents to relaunch credential modules on the next login. A kill loop is then activated, terminating essential applications such as Finder, Dock, browsers, and Terminal in a continuous cycle for up to 83 hours. This loop is designed to pressure the victim into entering the correct password. Additionally, Gatekeeper warnings are suppressed by killing NotificationCenter for approximately six hours.
The exfiltration of stolen data is carried out exclusively over Telegram, utilizing three bots with no centralized command-and-control server. The modules of the ClickLock Stealer are designed to cover their tracks by forging timestamps and deleting themselves, leaving behind only the GSocket backdoor.
This discovery highlights a growing trend in the macOS stealer ecosystem, with malware evolving to incorporate more sophisticated techniques. Group-IB advises users to be cautious of any website instructing them to paste commands into Terminal and recommends force-shutting down the system and booting into Safe Mode if applications start unexpectedly terminating.
The ClickLock Stealer serves as a reminder of the importance of cybersecurity vigilance and the need for users to stay informed about the latest threats targeting macOS systems.
