At a glance: ClickLock Stealer circumvents macOS protection features through aggressive process termination to force users to enter their passwords and then exfiltrate browsers, wallets and keychains.
IT security company Group-IB has discovered new malware called ClickLock Stealer that specifically targets macOS systems and steals sensitive data such as passwords and cryptocurrency wallets by blocking security processes and employing fraudulent authentication dialogs.
Group-IB identified ClickLock Stealer in early June 2026. Initial activity can be traced back to at least May 2026. So far, at least 100 affected systems in 33 countries have been documented, over half of them in Europe. The malware targets the following data types: access credentials from web browsers, password manager extensions, cryptocurrency wallets and their browser extensions, blockchain addresses from six different blockchains, macOS keychain, FTP credentials and shell history. The collected data is compressed and transmitted via Telegram bot to the attackers.
The infection begins with social engineering: victims are directed via SEO poisoning, social media posts or compromised websites to a page disguised as a Cloudflare security check. There, the user is presented with a Bash command to manually copy and paste into the macOS terminal. When executed, the system downloads a central control script, which in turn loads four additional modules: a credentials stealer, a cryptocurrency stealer, a keychain stealer and a backdoor program. After the data transfer, the theft modules are automatically deleted, while the backdoor program remains permanently.
The malware does not require security vulnerabilities and cannot be escalated automatically. Instead, it uses process termination as the primary mechanism to bypass protective barriers. The control script displays a fake macOS password window while simultaneously terminating all visible applications until the user enters his password. In parallel, a background loop continuously terminates the macOS NotificationCenter for approximately six hours, thereby suppressing all Gatekeeper and security warnings. When the malware requests the encryption key from Google Chrome from the keychain, it terminates all processes in the background until access is granted. Additionally, it actively terminates applications that the user could use to analyze the attack.
The exact initial distribution methods have not been fully clarified. However, Group-IB suspects SEO poisoning, social media campaigns or compromised websites as the attack vector.
Source: www.it-daily.net · Published July 19, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.