ClickLock Stealer: Paste Once, Lose Everything
A new modular macOS information stealer named ClickLock Stealer has been discovered targeting users primarily in Europe, North America, and the Middle East. The malware is likely distributed via ClickFix social engineering pages that trick victims into pasting malicious commands into Terminal. Once executed, it deploys four components: a credential stealer, a Keychain stealer targeting Chrome's encryption key, a comprehensive crypto wallet harvester, and a persistent GSocket-based backdoor. The malware employs an aggressive 'locker' technique, killing all visible applications except password dialogs to force user compliance. It targets data from eight browsers, 31 crypto wallet extensions, seven password managers, desktop wallets, macOS Keychain, and shell history. The campaign has compromised at least 100 victims across 33 countries since May 2026, using compromised WordPress domains and Telegram for command and control and exfiltration.
· unknown severity · unattributed attribution
Evidence and provenance
- Original source
- AlienVault OTX report ↗
- Published
- 2026-07-17T00:22:56.844000Z
- Confidence basis
- No actor match
- Record ID
f93beecd3000cd2c3afb
Use and citation
Verify the original report before making operational decisions. Cite this permanent page together with the original source, publication date, confidence level, and review status.