ClickLock Stealer Locks macOS Until Victims Enter Real Passwords and Exfiltrates Browser, Crypto and Keychain Data
Researchers at Group-IB have uncovered a previously unknown macOS infostealer that literally locks victims out of their computers until they supply valid login credentials. The newly identified threat, dubbed ClickLock Stealer, has been active since May 2026 and has already impacted at least 100 users in 33 countries.
The attack chain starts with a fake Cloudflare verification page. Unsuspecting users are instructed to copy and paste a command into the Terminal. While the victim watches a convincing browser-check animation with a progress bar, the script silently downloads four malicious modules hosted on compromised WordPress sites.
Once the modules are in place, a realistic macOS authentication dialog appears displaying the user’s real account name and requesting the password. ClickLock validates the entered password against the local directory service and transmits only working credentials to the operators. Pressing “Cancel” is ineffective: two LaunchAgent modules are installed that reactivate on every login.
One agent repeatedly closes every visible application every 210 milliseconds, leaving only the password-entry window on screen. The second agent forces the user to approve a genuine Keychain authorization prompt, allowing the malware to steal the encryption key for Chrome Safe Storage. A separate background process disables the Notification Center for several hours to prevent users from spotting suspicious activity.
The harvested data is extensive. ClickLock extracts credentials and cookies from eight browsers, 31 cryptocurrency-wallet browser extensions, seven password managers, eight desktop cryptocurrency wallets, the full Keychain database, Terminal command history, FTP account details and wallet addresses on six different blockchains. Stolen information is sent to the attackers through Telegram bots and compromised domains.
After completing its tasks, most modules delete themselves and tamper with file timestamps to hinder forensic analysis. A persistent, disguised GSocket backdoor remains on the system for potential future access. Investigators consider a connection to the ClickFix social-engineering technique highly likely, although the actual phishing pages used in this campaign have not yet been observed.
Related articles
Censys Exposes DarkSword iOS Exploit Platform and Coruna Crypto Wallet Stealer
Censys has disclosed the inner workings of DarkSword, a commercial platform that sells remote access to iOS devices, along with its associated malware Coruna that targets cryptocurrency wallet recovery keys. The infrastructure was exposed between September 15 and 17, allowing researchers to analyze the full attack chain starting from a WebKit and JavaScriptCore exploit delivered through the browser. After escaping the Safari sandbox and reaching the kernel, the platform deploys three layers including a flag, controller, and main implant. Coruna then scans the device for BIP39-compliant seed phrases stored in photos and Apple Notes across 19 targeted wallet applications such as MetaMask, Phantom, Trust Wallet, Coinbase, Exodus, imToken, Bitpie, and BitKeep. The exposed server contained 11 victim recovery keys, 179 directories of extracted data, and 75 operator accounts, indicating a structured commercial operation with agent accounts, commissions, and device quotas. Confirmed infections affect devices running iOS 16.1 and 16.3.1, while Apple has extended patches to additional iOS 18 devices. Maintaining updated iOS versions remains the primary defense against this threat.
How Malware Evades Sandboxes: Detection Techniques and Defense Strategies
Sandboxes have become a standard tool for analyzing suspicious files delivered via email, websites, messengers, and cloud storage. Modern malware often avoids detection by identifying virtual environments rather than directly attacking the sandbox. Techniques include checking for virtualization artifacts, system parameters, hardware signatures, network indicators, user activity, and timing delays. Reports such as Picus Red Report 2026 show technique T1497 returning to the top five most common MITRE ATT&CK methods. Examples like Blitz, GootLoader, and LummaC2 demonstrate environment checks and behavioral evasion. Effective defense requires combining multiple analysis methods, realistic sandbox profiles, pre-delivery inspection, and integration with other security controls.
Realtek Jungle SDK Flaw CVE-2021-35394 Fuels Cling Botnet Spread Across Routers
Researchers at Nozomi Networks have observed a sharp rise in exploitation attempts against CVE-2021-35394, a critical remote code execution vulnerability in the Realtek Jungle SDK. The flaw, rated 9.8 on the CVSS scale and disclosed five years ago, is being used to deploy the Cling botnet on routers and video recorders. The affected SDK is embedded in products from multiple vendors, leaving large numbers of devices exposed because firmware updates are rarely applied. Cling carries exploits for seven distinct vulnerabilities targeting Realtek, Linksys, MVPower, TBK, LB-LINK, FiberHome and China Mobile hardware. Once installed, the malware performs recursive scanning, spreads like a worm, manipulates TCP tunnels and proxies, and participates in DDoS attacks. Its command-and-control channel hides instructions inside STUN protocol transaction IDs, impersonating legitimate responses from Google public STUN servers. FortiGuard Labs has confirmed the findings and tracks the variant as ClingSTUN.
Attackers Abuse Legitimate Microsoft Defender Exclusions to Conceal Malware
Huntress researchers have detailed an evasion technique in which threat actors avoid disabling Microsoft Defender entirely. Instead, they create targeted exclusions for specific folders or file extensions, allowing malware to operate undetected while the protection status remains apparently active. These exclusions are configured through PowerShell commands, Windows Management Instrumentation, Group Policy, or direct registry modifications, all requiring administrator privileges after initial compromise. A registry key named HideExclusionsFromLocalAdmins can further conceal the list of exclusions from local administrators viewing the interface. The approach has been linked to campaigns involving GootKit in 2019, WhisperGate in 2022 that excluded the entire C: drive, and Muddled Libra in 2024. Defenders are advised to monitor registry changes directly, as this bypasses interface hiding, and to flag exclusions of entire drives or common directories such as temporary and downloads folders.