[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fwoC4DuCz305Z03P6uhb6kG6MPMhfk02eCv6jOA7GxxQ":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":27,"created_at":28,"published_at":29,"article":30,"tags":34,"podcasts":53},"4b673dc2-5804-45bc-9e61-18c84ff69de9","clicklock-macos-malware-tricks-users-into-surrendering-login-passwords-via-social-engineering","9f472d7b-46c3-4ad0-acfb-6d0c0f0cfb51","ClickLock macOS Malware Tricks Users Into Surrendering Login Passwords via Social Engineering","ClickLock exploits human trust rather than software vulnerabilities, using fake Cloudflare verification prompts (ClickFix lures) to deceive users into voluntarily entering their system login credentials. Once delivered, the malware establishes persistence via LaunchAgents and aggressively disrupts system processes for up to 83 hours, making it difficult for users to regain control. It then harvests an extremely broad range of sensitive data — including Keychain secrets, password-manager contents, browser data, and cryptocurrency wallets — before exfiltrating everything through Telegram. This attack highlights that even technically sophisticated platforms like macOS are not immune when the weakest link is an uninformed or pressured user. The long dwell time and multi-stage persistence make early detection and user awareness critical lines of defense.","**Immediate actions:**\n- Train all macOS users to recognize and refuse fake browser verification prompts (ClickFix\u002FCAPTCHA-style lures) that request system credentials.\n- Audit and review all LaunchAgent and LaunchDaemon entries on macOS endpoints for unauthorized persistence mechanisms.\n- Revoke and rotate any credentials or secrets that may have been exposed on potentially compromised macOS systems.\n\n**Long-term improvements:**\n- Enforce macOS System Integrity Protection (SIP) and Gatekeeper policies to block unsigned or unnotarized software from executing.\n- Implement privileged access management (PAM) solutions so that login passwords are never required to be entered into browser or third-party UI prompts.\n- Deploy an Endpoint Detection and Response (EDR) solution tuned to detect LaunchAgent creation, abnormal process termination loops, and unauthorized Keychain access on macOS.\n\n**Detection measures:**\n- Monitor for anomalous outbound connections to Telegram APIs or other messaging platforms used as command-and-control exfiltration channels.\n- Alert on repeated or bulk access to macOS Keychain, password manager files, and browser credential stores from non-standard processes.\n- Establish behavioral baselines for macOS endpoints to detect prolonged system process disruption patterns indicative of ClickLock's 83-hour interference loops.",[12,13,14,15,16,17,18,19,20,21,22,23,24,25,26],"CIS Control 14: Security Awareness and Skills Training","CIS Control 10: Malware Defenses","CIS Control 13: Network Monitoring and Defense","CIS Control 5: Account Management","NIST SP 800-53 AT-2: Security Awareness Training","NIST SP 800-53 AC-3: Access Enforcement","NIST SP 800-53 SI-3: Malicious Code Protection","NIST SP 800-53 AU-12: Audit Record Generation","NIST SP 800-53 IR-5: Incident Monitoring","NIST CSF DE.CM-1: Network Monitoring","MITRE ATT&CK T1059: Command and Scripting Interpreter","MITRE ATT&CK T1547.011: Launch Agent Persistence","MITRE ATT&CK T1056.002: GUI Input Capture","MITRE ATT&CK T1555.001: Keychain Credential Access","GDPR Article 32: Security of Processing","published","2026-07-16T22:20:25.145172+00:00","2026-07-16T22:20:24.855+00:00",{"id":7,"url":31,"slug":32,"title":33},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fnew-clicklock-macos-malware-traps-users-into-revealing-login-password\u002F","new-clicklock-macos-malware-traps-users-into-revealing-login-password-0a06e6","New ClickLock macOS malware traps users into revealing login password",[35,41,47],{"id":36,"name":37,"slug":38,"description":39,"color":40},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":42,"name":43,"slug":44,"description":45,"color":46},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":48,"name":49,"slug":50,"description":51,"color":52},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[54],{"id":55,"date":56,"edition":57,"title":58,"audio_url":59},"2b437a6b-6a78-45b3-a050-18586e1cb958","2026-07-17","morning","ThreatNoir Morning Brief — July 17","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-07-17\u002Fthreatnoir-morning-brief-2026-07-17.mp3"]