ClickLock Stealer: Paste Once, Lose Everything

    Date: 07/20/2026

    Severity: High

    Summary

    ClickLock Stealer is a newly discovered macOS malware that likely spreads through ClickFix phishing pages using compromised WordPress sites and Telegram infrastructure. It steals browser credentials, macOS Keychain data, password manager information, cryptocurrency wallet data, FTP credentials, and shell history, while using a modified GSocket backdoor for persistence. The campaign has targeted 100+ victims across 33 countries, with over 50% of victims located in Europe, and the malware is still under active development. 

    Indicators of Compromise (IOC) List 

    Domains/URLs

    panalobet.ph

    store.grafsynergy.com

    cottonbox.co.il

    https://panalobet.ph/wp-content/themes/twentytwenty/assets/fonts/chromer.txt

    https://panalobet.ph/wp-content/upgrade/zsh.txt

    https://panalobet.ph/wp-content/themes/twentytwenty/assets/images/finderv2.jpg

    https://panalobet.ph/wp-content/deng.php

    https://store.grafsynergy.com/media/goyim

    https://cottonbox.co.il/wp-content/hbd

    Hash

    b67aa4f598c0ea625a7409ea7884e10a7bc9c3ff

    8dda05168ea8610a2449419a47517bc32823d6ec

    0a1fb016bd10bac5455175c79aa4511e5ff1a330

    2fc970e25570532f9cbe33b7ebfe1f0383a7341a

    3ce0504ba65f8d56f83d7fef45faeaeb31e4e5aa9b872b56610b5f2558231caa

    3cee0c3bd463b6505e5df8fe7cb4f74a16c9f37ef96c98a8d7edcfb871cfbd4e

    37edd2381325114990174f341e9de27a1fbf77eeb579904460b991ebfb5418bf

    74ca82a10e5e8697db96b8cb28280ff9fd0371eaafa32eb1d785320b962e19f4

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    domainname like "panalobet.ph" or url like "panalobet.ph" or siteurl like "panalobet.ph" or domainname like "https://cottonbox.co.il/wp-content/hbd" or url like "https://cottonbox.co.il/wp-content/hbd" or siteurl like "https://cottonbox.co.il/wp-content/hbd" or domainname like "https://panalobet.ph/wp-content/themes/twentytwenty/assets/images/finderv2.jpg" or url like "https://panalobet.ph/wp-content/themes/twentytwenty/assets/images/finderv2.jpg" or siteurl like "https://panalobet.ph/wp-content/themes/twentytwenty/assets/images/finderv2.jpg" or domainname like "https://panalobet.ph/wp-content/themes/twentytwenty/assets/fonts/chromer.txt" or url like "https://panalobet.ph/wp-content/themes/twentytwenty/assets/fonts/chromer.txt" or siteurl like "https://panalobet.ph/wp-content/themes/twentytwenty/assets/fonts/chromer.txt" or domainname like "https://panalobet.ph/wp-content/deng.php" or url like "https://panalobet.ph/wp-content/deng.php" or siteurl like "https://panalobet.ph/wp-content/deng.php" or domainname like "cottonbox.co.il" or url like "cottonbox.co.il" or siteurl like "cottonbox.co.il" or domainname like "store.grafsynergy.com" or siteurl like "store.grafsynergy.com" or url like "store.grafsynergy.com" or domainname like "https://panalobet.ph/wp-content/upgrade/zsh.txt" or siteurl like "https://panalobet.ph/wp-content/upgrade/zsh.txt" or url like "https://panalobet.ph/wp-content/upgrade/zsh.txt" or domainname like "https://store.grafsynergy.com/media/goyim" or siteurl like "https://store.grafsynergy.com/media/goyim" or url like "https://store.grafsynergy.com/media/goyim"

    Detection Query 2 :

    sha1hash IN ("d9617710d4ed8e9b87f6fee0b7014c4101effba0","8dda05168ea8610a2449419a47517bc32823d6ec","b67aa4f598c0ea625a7409ea7884e10a7bc9c3ff","0a1fb016bd10bac5455175c79aa4511e5ff1a330","2fc970e25570532f9cbe33b7ebfe1f0383a7341a")

    Detection Query 3 :

    sha256hash IN ("74ca82a10e5e8697db96b8cb28280ff9fd0371eaafa32eb1d785320b962e19f4","37edd2381325114990174f341e9de27a1fbf77eeb579904460b991ebfb5418bf","3cee0c3bd463b6505e5df8fe7cb4f74a16c9f37ef96c98a8d7edcfb871cfbd4e","3ce0504ba65f8d56f83d7fef45faeaeb31e4e5aa9b872b56610b5f2558231caa")

    Reference:    

    https://www.group-ib.com/blog/clicklock-stealer-macos-malware/                      


    Tags

    MalwareStealerClickFixPhishingWordPressTelegramCredential HarvestingcryptocurrencyBackdoorEurope

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags