Overview
- Security firm Group-IB publicly detailed ClickLock Stealer in mid-July and linked the campaign to roughly 100 victims across 33 countries, saying the operation has been active since May 2026.
- The attack starts with a ClickFix-style phishing page that tells a user to copy and paste a Terminal command, which runs a malicious shell script without needing software exploits or admin elevation.
- After the script runs the malware shows a fake macOS password prompt and, if the user refuses, repeatedly kills visible apps roughly every 210 milliseconds to force compliance.
- When a user enters their password the malware triggers a real Keychain access prompt to steal Chrome’s 'Safe Storage' AES key and then harvests browser passwords, password‑manager data, wallet files and other credentials before exfiltrating them to Telegram.
- Although most modules self-delete, a modified GSocket reverse shell is installed for persistence and vendors have rolled out defenses such as macOS Tahoe 26.4 clipboard warnings and browser paste protections while researchers advise revoking credentials, changing passwords from clean devices, and avoiding pasted commands from untrusted pages.