A Fake Prompt Becomes the Password Theft Point

ClickLock turns a fake password prompt into the trust anchor. It does not need to steal a password by guessing. It makes the Mac painful enough to use that some victims will type a valid one, and that one entry unlocks browser sessions, Chrome’s decryption key, Keychain data, and wallet storage in the same run. Group-IB says the campaign has hit at least 100 victims in 33 countries since May. The malware kills Finder, browsers, Terminal, Activity Monitor, and other apps in tight loops until the user enters a password that it validates locally, so only a real password reaches the operator. It also targets Chrome credentials and cookies, MetaMask, Phantom, FileZilla, and other wallet and account data. The forward risk is bigger than one cleaned Mac. Any environment that relies on browser-saved passwords, sync tokens, or wallet extensions can lose reusable access material when a user is coerced into one successful prompt.

Part of the PlainSec briefing for 2026-07-17

Sources