ClickLock Stealer Mac Removal: Stop the Password Trap

Brendan Smith
Brendan Smith - Cybersecurity Analyst
11 Min Read
ClickLock Stealer password prompt closing Mac applications
A fake password prompt remains while ClickLock closes Mac applications.

ClickLock Stealer is macOS malware that can keep closing apps while a fake password dialog remains on screen. If this starts after you pasted a “verification” command into Terminal, do not enter your Mac password, approve Keychain access, or grant Terminal Full Disk Access. Disconnect the Mac from Wi-Fi and Ethernet, shut it down, and use a separate trusted device for password and session recovery.

Restarting can stop the immediate pressure, but it is not proof of cleanup. Public analysis found two temporary LaunchAgents plus a separate GSocket reverse shell disguised as an iCloud component. That backdoor can remain after the password-stealing modules delete themselves.

What Is ClickLock Stealer?

ClickLock is a modular information stealer analyzed by Group-IB in July 2026. The researchers started with the malicious shell script itself, not an observed delivery page. They assessed with high confidence that the script was designed for a ClickFix-style lure: a fake Cloudflare or browser-verification page tells the visitor to copy a command into Terminal.

After the command runs, the script displays a fake verification animation while downloading additional components. If the first password prompt is canceled, it can create LaunchAgents that run at the next login. One component repeatedly terminates Finder, Dock, browsers, Terminal, Activity Monitor, System Settings, and other interactive apps every 210 milliseconds. The fake password dialog stays usable, pressuring the victim to type the login password.

This is not a macOS exploit and the password window is not proof that Apple requested authentication. The attack works because the user runs a command and then trusts a prompt created by that command.

What to Do Based on What Happened

What happened Risk and what to do
You only saw the fake verification page Close the tab. Do not copy or run its command. Clear the site from browser history if helpful, then update macOS and the browser. No ClickLock execution is established by seeing the page alone.
You pasted the command but canceled every prompt Treat the Mac as compromised. The script can download components and establish persistence before a password is entered. Disconnect it, shut it down, start in Safe Mode, and check the documented artifacts below.
You entered the Mac login password Assume the password was exposed. From a separate trusted device, change it anywhere it was reused, secure the Apple Account, and revoke important web sessions after containing the Mac.
You approved a Keychain prompt or Full Disk Access Assume browser cookies, saved credentials, Keychain material, password-manager data, wallet files, and other protected data may have been accessible. Prioritize session revocation, password-manager recovery, wallet migration, and a full rebuild if trust cannot be restored.

How to Regain Control of the Mac

  1. Do not feed the prompt. Do not type the password, approve a Keychain request, or add Terminal to Full Disk Access. A real website does not need a Terminal command to verify that you are human.
  2. Disconnect networking. Turn off Wi-Fi and unplug Ethernet if the controls still work. If ClickLock keeps closing System Settings, move directly to a forced shutdown.
  3. Shut down the Mac. Press and hold the power button until it turns off. This interrupts the active loop but does not remove LaunchAgents or the reverse shell.
  4. Start in Safe Mode. On Apple silicon, hold the power button until startup options appear, select the startup volume, hold Shift, and choose Continue in Safe Mode. On an Intel Mac, turn it on and immediately hold Shift until the login window appears.
  5. Stay offline while checking persistence. Do not sign in to email, a password manager, exchanges, wallets, or administrator portals from the suspect Mac.

Apple now warns when a website, chat, or message appears to be the source of a Terminal paste. Treat that warning as a stop sign. Do not select an override merely because the page claims that the command is a CAPTCHA, browser fix, codec, update, or account check.

Check the Documented ClickLock Artifacts

Group-IB documented a hidden staging directory at ~/.cacheb/ and two LaunchAgents named com.authirity.plist and com.chromer.plist in ~/Library/LaunchAgents/. The misspelling in authirity is part of the observed artifact. The same research found a separate GSocket component under ~/Library/Application Support/iCloudsync with a process masquerading as SystemUIServerl—ending with a lowercase letter “l,” not the legitimate SystemUIServer name.

These read-only checks can help confirm the exact locations while the Mac is in Safe Mode:

ls -la "$HOME/.cacheb" 2>/dev/null
ls -la "$HOME/Library/LaunchAgents" 2>/dev/null
ls -la "$HOME/Library/Application Support/iCloudsync" 2>/dev/null
crontab -l 2>/dev/null
grep -nE 'iCloudsync|SystemUIServerl' "$HOME/.zshrc" "$HOME/.zprofile" "$HOME/.bash_profile" "$HOME/.bashrc" 2>/dev/null

Do not delete every LaunchAgent, cron entry, or file with “iCloud” in its name. Macs and legitimate apps use many startup items. Compare the exact names, paths, contents, and creation time with the incident. If the documented ClickLock artifacts are present, keep the Mac offline and preserve a copy for an incident responder before removing them from their launch locations.

The GSocket component matters because it does not follow the same cleanup behavior as the password-stealing modules. Its installer can add a LaunchAgent, a cron entry, and shell-startup changes. Removing only ~/.cacheb/ or the two temporary LaunchAgents can leave remote access behind.

When Manual Cleanup Is Not Enough

A confirmed reverse shell changes the trust decision. If iCloudsync, SystemUIServerl, an unfamiliar cron entry, or a related shell-startup modification is present, the safest recovery may be to back up personal documents and reinstall macOS from Recovery rather than assume that deleting visible files removed every change.

Do not restore unknown apps, scripts, browser profiles, shell configuration files, or all of ~/Library from the same backup. Reinstall applications from their official sources and review Login Items & Extensions before reconnecting the Mac.

ClickLock overlaps with other Mac ClickFix infections, but the family name matters. The Odyssey Stealer Mac guide covers a different stealer and different artifacts. Use ClickLock’s exact paths only when the symptoms and evidence match; do not label every fake verification command as this family.

Recover Passwords, Sessions, and Wallets From a Clean Device

Contain the Mac first, then use a separate trusted phone or computer for account recovery. Changing passwords on the infected Mac can expose the new credentials to the attacker.

  1. Secure the primary email account. Change its password, sign out other sessions, review forwarding rules and recovery methods, and confirm multi-factor authentication.
  2. Secure the Apple Account. Change the password, review trusted devices and phone numbers, and remove anything unfamiliar.
  3. Reset the password manager. Follow its compromised-device procedure, rotate the master password, revoke sessions, and review emergency or recovery access.
  4. Revoke browser sessions. Password changes do not always invalidate stolen cookies. Use each important service’s “sign out everywhere” or device/session page.
  5. Protect cryptocurrency. If seed phrases, wallet files, or browser-wallet data were accessible, create a new wallet on a trusted device and move assets. A password change does not make an exposed seed phrase safe.
  6. Rotate developer and remote-access secrets. Replace SSH keys, FileZilla credentials, repository tokens, cloud CLI credentials, VPN access, and other secrets that existed on the Mac.
  7. Watch for follow-on abuse. Review financial accounts, exchange withdrawals, email logins, password resets, and messages sent from compromised accounts.

For the broader reason session theft can survive a password-only response, see the infostealer recovery overview.

How to Avoid the Next Fake Verification Command

  • Never paste a command into Terminal because a website calls it a CAPTCHA or verification step.
  • Stop when macOS says a pasted command came from a website, chat, or message.
  • Do not grant Terminal Full Disk Access to complete a web flow.
  • Download apps and updates from the developer’s official site or the Mac App Store.
  • Treat unexpected password or Keychain prompts as suspicious when they appear immediately after a copied command.
  • Keep macOS and browsers current so built-in ClickFix warnings and known-malware blocks are available.

FAQ

Is ClickLock a real Mac lock screen?

No. The analyzed malware creates a fake password dialog and repeatedly closes other apps so that the prompt appears unavoidable. It does not need a macOS lock-screen exploit.

If I canceled the password prompt, am I safe?

Not necessarily. The initial script can download modules and create persistence before it captures a password. Check the documented LaunchAgents, hidden cache directory, and residual iCloudsync backdoor path.

Does force-shutting down remove ClickLock?

No. A shutdown stops the immediate process loop, but LaunchAgents, cron entries, shell-startup changes, or the GSocket reverse shell may run again. Use Safe Mode for inspection and consider reinstalling macOS when a backdoor is confirmed.

Should I change passwords on the affected Mac?

No. Use a separate trusted device after isolating the Mac. Prioritize email, the Apple Account, password managers, browser sessions, financial accounts, developer secrets, and wallets.

References

  1. Martynyuk, B. “ClickLock Stealer: Paste Once, Lose Everything.” Group-IB Threat Intelligence, July 16, 2026, accessed July 23, 2026. group-ib.com.
  2. Apple. “If your Mac blocks a Terminal command paste or script.” Apple Support, accessed July 23, 2026. support.apple.com.
  3. Apple. “Start up your Mac in safe mode.” macOS User Guide, accessed July 23, 2026. support.apple.com.
Share This Article
Cybersecurity Analyst
Follow:
Brendan Smith has spent over 15 years knee-deep in cybersecurity, chasing down malware from the gritty reverse-engineering of old-school trojans all the way to wrangling full-blown incident responses for small-to-medium businesses that couldn’t afford a full-blown breach. Over at Gridinsoft, he’s the guy piecing together those double-checked guides on nasty stuff like AsyncRAT ransomware—take last year, for instance, when his breakdowns caught more than 200 sneaky variants right in live scans, knocking user cleanup jobs down by a solid 40% and saving folks hours of headache.
Leave a Comment

AI Assistant

Hello! 👋 How can I help you today?