ClickLock Stealer macOS forced-interaction infostealer activity
Malware Activity
Summary
Hide ▲
Show ▼
ClickLock Stealer is a macOS information-stealing malware that uses a ClickFix-style paste into Terminal and a fake system dialog to coerce users into entering their macOS login password. Group-IB said the malware affected at least 100 systems across 33 countries since May, remained undetected by security vendors on VirusTotal when analyzed, and was first submitted on June 9. The activity can drop LaunchAgents for persistence, repeatedly terminate visible apps to keep the desktop unusable, and exfiltrate stolen data through Telegram. It targets browser data, password-manager data, crypto wallet material, Keychain-related information, and can install a persistent backdoor for ongoing remote access.
Related Happenings
Steam discussion forums ClickFix campaign deploying XMRig miners
Campaign
H score34
First: 26.07.2026 01:37
Last: 26.07.2026 01:37
Sources 1
About this happening:
An ongoing ClickFix campaign on Steam discussion forums is tricking users into running PowerShell commands that install XMRig cryptominers. The operation abuses he...
Steam discussion forums ClickFix campaign deploying XMRig miners
CampaignAbout this happening: An ongoing ClickFix campaign on Steam discussion forums is tricking users into running PowerShell commands that install XMRig cryptominers. The operation abuses he...
PylangGhost and GolangGhost ClickFix RAT delivery on Windows and macOS
Malware Activity
H score29
First: 21.07.2026 12:30
Last: 21.07.2026 12:30
Sources 1
About this happening:
The PylangGhost and GolangGhost malware operation now uses ClickFix interview portals to install remote access trojans on Windows and macOS, putting Web3 a...
PylangGhost and GolangGhost ClickFix RAT delivery on Windows and macOS
Malware ActivityAbout this happening: The PylangGhost and GolangGhost malware operation now uses ClickFix interview portals to install remote access trojans on Windows and macOS, putting Web3 a...
ACR Stealer browser credential and document theft activity
Malware Activity
H score29
First: 17.07.2026 11:56
Last: 17.07.2026 11:56
Sources 1
About this happening:
ACR Stealer is driving a surge of browser credential and document theft against enterprise customers. Microsoft said activity climbed from late April to mid-June...
ACR Stealer browser credential and document theft activity
Malware ActivityAbout this happening: ACR Stealer is driving a surge of browser credential and document theft against enterprise customers. Microsoft said activity climbed from late April to mid-June...
ClickFix-based TELEPUZ distribution campaign
Campaign
H score35
First: 16.07.2026 15:50
Last: 16.07.2026 15:50
Sources 1
About this happening:
The ClickFix-based TELEPUZ distribution campaign is pushing TELEPUZ through websites infected with lures, increasing the chance that victims run malicious commands and...
ClickFix-based TELEPUZ distribution campaign
CampaignAbout this happening: The ClickFix-based TELEPUZ distribution campaign is pushing TELEPUZ through websites infected with lures, increasing the chance that victims run malicious commands and...
ClickLock ClickFix macOS targeting campaign
Campaign
H score33
First: 16.07.2026 15:33
Last: 16.07.2026 15:33
Sources 1
How related:
According to new research from Group-IB published on June 16, the malware, dubbed ClickLock Stealer, has hit at least 100 victims across 33 countries in about two months, with more than half in Europe.
About this happening:
Group-IB reported a ClickLock macOS campaign that uses ClickFix paste-a-command lures and coercive app-killing loops to force victims to enter their system login...
ClickLock ClickFix macOS targeting campaign
CampaignHow related: According to new research from Group-IB published on June 16, the malware, dubbed ClickLock Stealer, has hit at least 100 victims across 33 countries in about two months, with more than half in Europe.
About this happening: Group-IB reported a ClickLock macOS campaign that uses ClickFix paste-a-command lures and coercive app-killing loops to force victims to enter their system login...
Timeline
-
16.07.2026 15:33 4 articles · 13d ago
ClickLock Stealer macOS forced-interaction infostealer activity
Initial DisclosureThe delivery phase uses a ClickFix-style paste into Terminal and a fake system dialog to push the victim toward running the payload. If the user cancels, the script drops LaunchAgents and exits before the coercion loop begins.
Show sources
- New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password — thehackernews.com — 16.07.2026 15:33
- New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password — thehackernews.com — 16.07.2026 15:33
- Modular macOS Stealer Uses Kill Loops to Force Password Entry — www.infosecurity-magazine.com — 16.07.2026 16:30
- New ClickLock macOS malware traps users into revealing login password — www.bleepingcomputer.com — 17.07.2026 00:52