ClickLock ClickFix macOS targeting campaign
Campaign
Summary
Hide ▲
Show ▼
Group-IB reported a ClickLock macOS campaign that uses ClickFix paste-a-command lures and coercive app-killing loops to force victims to enter their system login password. The operation has reached at least 100 targets across 33 countries since May 2026, with more than half in Europe. Group-IB also said the orchestrator script uploaded to VirusTotal on June 9 had zero detections, while the malware hid the cursor, showed a fake Cloudflare progress animation, pulled modules from compromised sites, stole Keychain and wallet data, and exfiltrated through Telegram.
Related Happenings
Steam discussion forums ClickFix campaign deploying XMRig miners
Campaign
H score34
First: 26.07.2026 01:37
Last: 26.07.2026 01:37
Sources 1
About this happening:
An ongoing ClickFix campaign on Steam discussion forums is tricking users into running PowerShell commands that install XMRig cryptominers. The operation abuses he...
Steam discussion forums ClickFix campaign deploying XMRig miners
CampaignAbout this happening: An ongoing ClickFix campaign on Steam discussion forums is tricking users into running PowerShell commands that install XMRig cryptominers. The operation abuses he...
ClickFix-based TELEPUZ distribution campaign
Campaign
H score35
First: 16.07.2026 15:50
Last: 16.07.2026 15:50
Sources 1
About this happening:
The ClickFix-based TELEPUZ distribution campaign is pushing TELEPUZ through websites infected with lures, increasing the chance that victims run malicious commands and...
ClickFix-based TELEPUZ distribution campaign
CampaignAbout this happening: The ClickFix-based TELEPUZ distribution campaign is pushing TELEPUZ through websites infected with lures, increasing the chance that victims run malicious commands and...
ClickLock Stealer macOS forced-interaction infostealer activity
Malware Activity
H score27
First: 16.07.2026 15:33
Last: 16.07.2026 15:33
Sources 1
How related:
A new macOS information-stealing malware dubbed ClickLock terminates all visible processes to force users into entering their system login password.
About this happening:
ClickLock Stealer is a macOS information-stealing malware that uses a ClickFix-style paste into Terminal and a fake system dialog to coerce users into entering the...
ClickLock Stealer macOS forced-interaction infostealer activity
Malware ActivityHow related: A new macOS information-stealing malware dubbed ClickLock terminates all visible processes to force users into entering their system login password.
About this happening: ClickLock Stealer is a macOS information-stealing malware that uses a ClickFix-style paste into Terminal and a fake system dialog to coerce users into entering the...
ClickFix mitigation guidance for Windows and macOS
Defensive Guidance
H score34
First: 30.06.2026 15:00
Last: 30.06.2026 15:00
Sources 1
About this happening:
Organizations are being urged to harden defenses against ClickFix on Windows and macOS, reducing the chance that social-engineering lures can turn trusted dialogs into...
ClickFix mitigation guidance for Windows and macOS
Defensive GuidanceAbout this happening: Organizations are being urged to harden defenses against ClickFix on Windows and macOS, reducing the chance that social-engineering lures can turn trusted dialogs into...
Y2K Operators Millenium RAT social-engineering distribution campaign
Campaign
H score73
First: 29.06.2026 17:30
Last: 29.06.2026 17:30
Sources 1
About this happening:
The Y2K Operators are running a social-engineering distribution campaign that spreads Millenium RAT through booby-trapped downloads, exposing users to remote compr...
Y2K Operators Millenium RAT social-engineering distribution campaign
CampaignAbout this happening: The Y2K Operators are running a social-engineering distribution campaign that spreads Millenium RAT through booby-trapped downloads, exposing users to remote compr...
Timeline
-
16.07.2026 03:00 1 articles · 14d ago
VirusTotal shows zero detections for the orchestrator script
Technical Analysis UpdateGroup-IB uploaded the orchestrator script to VirusTotal on June 9 and found zero detections when it analyzed the file, indicating the sample was still largely unrecognized by scanners.
Show sources
- New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password — thehackernews.com — 16.07.2026 15:33
-
16.07.2026 03:00 4 articles · 14d ago
Group-IB discloses a ClickLock campaign spanning 33 countries
Initial DisclosureGroup-IB says the ClickLock campaign has reached at least 100 targets across 33 countries since May 2026, with more than half in Europe, indicating an active macOS ClickFix operation targeting victims for password and credential theft.
Show sources
- New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password — thehackernews.com — 16.07.2026 15:33
- New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password — thehackernews.com — 16.07.2026 15:33
- Modular macOS Stealer Uses Kill Loops to Force Password Entry — www.infosecurity-magazine.com — 16.07.2026 16:30
- New ClickLock macOS malware traps users into revealing login password — www.bleepingcomputer.com — 17.07.2026 00:52