A newly reported macOS malware campaign is tricking users into infecting their own Macs and then stealing passwords, browser data, and cryptocurrency wallet information. Group-IB says ClickLock Stealer has targeted at least 100 users in 33 countries since late May 2026, likely via ClickFix-style fake Cloudflare verification pages that tell victims to paste a bash command into Terminal. The malware kills visible processes and NotificationCenter to suppress warnings, uses fake password prompts to capture credentials, steals Keychain and browser secrets, and exfiltrates data to a Telegram bot.
Why it matters: Mac users are affected even without a software exploit because the attack relies on social engineering and abuse of built-in tools. Organizations should warn users not to paste commands from websites into Terminal, review macOS detections and process-killing behavior, and treat exposed passwords, wallet secrets, and browser data as compromised.
Bill Toulas
2026.07.16
98% relevant
This source adds detailed technical analysis of the same ClickLock macOS malware campaign, including its fake Cloudflare Terminal lure, password-coercion loops, LaunchAgent persistence, Telegram exfiltration, targeted data types, and an estimate of at least 100 infected systems in 33 countries.
Eduard Kovacs
2026.07.16
100% relevant
This article establishes a distinct new malware campaign, naming ClickLock Stealer, its macOS-focused theft and evasion techniques, likely delivery method, and observed victim scope.
← Back to all stories