Date: 07/20/2026
Severity: High
Summary
ClickLock Stealer is a newly discovered macOS malware that likely spreads through ClickFix phishing pages using compromised WordPress sites and Telegram infrastructure. It steals browser credentials, macOS Keychain data, password manager information, cryptocurrency wallet data, FTP credentials, and shell history, while using a modified GSocket backdoor for persistence. The campaign has targeted 100+ victims across 33 countries, with over 50% of victims located in Europe, and the malware is still under active development.
Indicators of Compromise (IOC) List
Domains/URLs | panalobet.ph store.grafsynergy.com cottonbox.co.il https://panalobet.ph/wp-content/themes/twentytwenty/assets/fonts/chromer.txt https://panalobet.ph/wp-content/upgrade/zsh.txt https://panalobet.ph/wp-content/themes/twentytwenty/assets/images/finderv2.jpg https://panalobet.ph/wp-content/deng.php https://store.grafsynergy.com/media/goyim https://cottonbox.co.il/wp-content/hbd |
Hash | b67aa4f598c0ea625a7409ea7884e10a7bc9c3ff
8dda05168ea8610a2449419a47517bc32823d6ec
0a1fb016bd10bac5455175c79aa4511e5ff1a330
2fc970e25570532f9cbe33b7ebfe1f0383a7341a
3ce0504ba65f8d56f83d7fef45faeaeb31e4e5aa9b872b56610b5f2558231caa
3cee0c3bd463b6505e5df8fe7cb4f74a16c9f37ef96c98a8d7edcfb871cfbd4e
37edd2381325114990174f341e9de27a1fbf77eeb579904460b991ebfb5418bf
74ca82a10e5e8697db96b8cb28280ff9fd0371eaafa32eb1d785320b962e19f4
|
Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection
Detection Query 1 : | domainname like "panalobet.ph" or url like "panalobet.ph" or siteurl like "panalobet.ph" or domainname like "https://cottonbox.co.il/wp-content/hbd" or url like "https://cottonbox.co.il/wp-content/hbd" or siteurl like "https://cottonbox.co.il/wp-content/hbd" or domainname like "https://panalobet.ph/wp-content/themes/twentytwenty/assets/images/finderv2.jpg" or url like "https://panalobet.ph/wp-content/themes/twentytwenty/assets/images/finderv2.jpg" or siteurl like "https://panalobet.ph/wp-content/themes/twentytwenty/assets/images/finderv2.jpg" or domainname like "https://panalobet.ph/wp-content/themes/twentytwenty/assets/fonts/chromer.txt" or url like "https://panalobet.ph/wp-content/themes/twentytwenty/assets/fonts/chromer.txt" or siteurl like "https://panalobet.ph/wp-content/themes/twentytwenty/assets/fonts/chromer.txt" or domainname like "https://panalobet.ph/wp-content/deng.php" or url like "https://panalobet.ph/wp-content/deng.php" or siteurl like "https://panalobet.ph/wp-content/deng.php" or domainname like "cottonbox.co.il" or url like "cottonbox.co.il" or siteurl like "cottonbox.co.il" or domainname like "store.grafsynergy.com" or siteurl like "store.grafsynergy.com" or url like "store.grafsynergy.com" or domainname like "https://panalobet.ph/wp-content/upgrade/zsh.txt" or siteurl like "https://panalobet.ph/wp-content/upgrade/zsh.txt" or url like "https://panalobet.ph/wp-content/upgrade/zsh.txt" or domainname like "https://store.grafsynergy.com/media/goyim" or siteurl like "https://store.grafsynergy.com/media/goyim" or url like "https://store.grafsynergy.com/media/goyim" |
Detection Query 2 : | sha1hash IN ("d9617710d4ed8e9b87f6fee0b7014c4101effba0","8dda05168ea8610a2449419a47517bc32823d6ec","b67aa4f598c0ea625a7409ea7884e10a7bc9c3ff","0a1fb016bd10bac5455175c79aa4511e5ff1a330","2fc970e25570532f9cbe33b7ebfe1f0383a7341a")
|
Detection Query 3 : | sha256hash IN ("74ca82a10e5e8697db96b8cb28280ff9fd0371eaafa32eb1d785320b962e19f4","37edd2381325114990174f341e9de27a1fbf77eeb579904460b991ebfb5418bf","3cee0c3bd463b6505e5df8fe7cb4f74a16c9f37ef96c98a8d7edcfb871cfbd4e","3ce0504ba65f8d56f83d7fef45faeaeb31e4e5aa9b872b56610b5f2558231caa")
|
Reference:
https://www.group-ib.com/blog/clicklock-stealer-macos-malware/