ClickLock Stealer Locks macOS Until Victims Enter Real Passwords and Exfiltrates Browser, Crypto and Keychain Data
Researchers at Group-IB have uncovered a previously unknown macOS infostealer that literally locks victims out of their computers until they supply valid login credentials. The newly identified threat, dubbed ClickLock Stealer, has been active since May 2026 and has already impacted at least 100 users in 33 countries.
The attack chain starts with a fake Cloudflare verification page. Unsuspecting users are instructed to copy and paste a command into the Terminal. While the victim watches a convincing browser-check animation with a progress bar, the script silently downloads four malicious modules hosted on compromised WordPress sites.
Once the modules are in place, a realistic macOS authentication dialog appears displaying the user’s real account name and requesting the password. ClickLock validates the entered password against the local directory service and transmits only working credentials to the operators. Pressing “Cancel” is ineffective: two LaunchAgent modules are installed that reactivate on every login.
One agent repeatedly closes every visible application every 210 milliseconds, leaving only the password-entry window on screen. The second agent forces the user to approve a genuine Keychain authorization prompt, allowing the malware to steal the encryption key for Chrome Safe Storage. A separate background process disables the Notification Center for several hours to prevent users from spotting suspicious activity.
The harvested data is extensive. ClickLock extracts credentials and cookies from eight browsers, 31 cryptocurrency-wallet browser extensions, seven password managers, eight desktop cryptocurrency wallets, the full Keychain database, Terminal command history, FTP account details and wallet addresses on six different blockchains. Stolen information is sent to the attackers through Telegram bots and compromised domains.
After completing its tasks, most modules delete themselves and tamper with file timestamps to hinder forensic analysis. A persistent, disguised GSocket backdoor remains on the system for potential future access. Investigators consider a connection to the ClickFix social-engineering technique highly likely, although the actual phishing pages used in this campaign have not yet been observed.
Related articles
MacSync Malware Evolves to Steal Cryptocurrency and Conceal Components in iCloud
Updated MacSync malware for macOS now arrives bundled with a stealer and backdoor, allowing attackers to harvest browser history, cookies, passwords, Telegram data, and cryptocurrency wallet details while maintaining persistent remote access. Discovered by Kaspersky researchers in September 2026, the new variant uses a multi-stage infection chain that begins with a fake application download, such as a document collaboration tool or crypto wallet. One component is delivered through a publicly shared iCloud calendar entry in ICS format, bypassing traditional loaders. After execution, MacSync requests administrator credentials, displays a fake macOS damage notification, and installs the stealer alongside a Finder-masquerading backdoor. The backdoor enables arbitrary code execution, file theft, browser extension installation, and replacement of the legitimate Ledger application with a malicious version to drain cryptocurrency funds. Users are advised to download software only from trusted sources and remain cautious of unexpected administrator password prompts.
Network Traffic Analysis Reveals 75% Malware Threats Over 10 Months of Monitoring
Positive Technologies analyzed anonymized data from PT Sandbox and PT Network Attack Discovery collected between October 2025 and July 2026. The study found that malicious software accounted for 75% of all detected threats in organizational network traffic. Information-stealing trojans made up 24% of malware samples, with 85% of those focused on credential theft. RATs, loaders, and ransomware each represented smaller but high-impact shares. Legacy vulnerabilities such as CVE-2017-0199 and CVE-2017-11882 remained active attack vectors. Activity from groups including MustangPanda, TA505, and APT37 was observed across finance, manufacturing, and government sectors.
HEAVYGRAM Spyware Uses Telegram Bots for Command and Control Against Iranian Targets
Researchers at Group-IB have published a detailed analysis of HEAVYGRAM, a spyware family that abuses the Telegram messaging platform as its command-and-control infrastructure. The malware family was first observed in the second half of 2023 and has since been linked with moderate confidence to the Handala Hack group. Instead of operating dedicated servers, the operators rely on Telegram bots, accounts, and groups to register infected hosts, receive commands, exfiltrate stolen data, and deliver additional payloads. Once active, HEAVYGRAM captures screenshots, records audio, harvests cached files, and steals data from Telegram Desktop installed on the victim machine. The campaign primarily targets Iranian journalists, dissidents, and individuals opposed to the Iranian government. Infection vectors include malicious files distributed via messengers, disguised as legitimate applications such as Pictory, KeePass, or Telegram-related tools, sometimes delivered as HTML applications or scripts.
KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens in Brazil
Elastic Security Labs researchers have detailed the operations of the KREMLIN banking malware, tracked under the identifier REF9334, which targets Chrome and Edge browsers to harvest credentials and session tokens. The campaign focuses almost exclusively on Brazil, with 98 percent of the 1,515 identified infections located in the country and impersonating a dozen Brazilian banks. Infection begins with multi-stage JavaScript loaders disguised as banking documents, invoices, or corporate papers that require manual execution by the victim. The loaders then deploy C++ installers and malicious browser extensions that modify the Secure Preferences file, enable developer mode, and overwrite protection objects with forged metadata using a technique called Phantom Extension. Once active, the extension collects session tokens, cookies, sessionStorage and localStorage data, 15 days of browsing history, screenshots, open tab information, and full HTML of visited pages. The operation has run since May 2025 across seven distinct campaigns and began using Ethereum smart contracts for infrastructure on 19 May 2026.