ClickLock Stealer targets macOS users with fake Cloudflare checks to steal passwords and cryptocurrency

A newly reported macOS malware campaign is tricking users into infecting their own Macs and then stealing passwords, browser data, and cryptocurrency wallet information. Group-IB says ClickLock Stealer has targeted at least 100 users in 33 countries since late May 2026, likely via ClickFix-style fake Cloudflare verification pages that tell victims to paste a bash command into Terminal. The malware kills visible processes and NotificationCenter to suppress warnings, uses fake password prompts to capture credentials, steals Keychain and browser secrets, and exfiltrates data to a Telegram bot.
Why it matters: Mac users are affected even without a software exploit because the attack relies on social engineering and abuse of built-in tools. Organizations should warn users not to paste commands from websites into Terminal, review macOS detections and process-killing behavior, and treat exposed passwords, wallet secrets, and browser data as compromised.

Sources

New ClickLock macOS malware traps users into revealing login password
Bill Toulas 2026.07.16 98% relevant
This source adds detailed technical analysis of the same ClickLock macOS malware campaign, including its fake Cloudflare Terminal lure, password-coercion loops, LaunchAgent persistence, Telegram exfiltration, targeted data types, and an estimate of at least 100 infected systems in 33 countries.
‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing
Eduard Kovacs 2026.07.16 100% relevant
This article establishes a distinct new malware campaign, naming ClickLock Stealer, its macOS-focused theft and evasion techniques, likely delivery method, and observed victim scope.
← Back to all stories