Hackers Use Paste-and-Run Commands to Deploy ClickLock Stealer Against Mac Users
ID: 3ee84d63-cfe1-5d91-a36c-0ab699432dee
STIX ID: report--3ee84d63-cfe1-5d91-a36c-0ab699432dee
Feed Name: GBHackers
ClickLock Stealer is an actively observed macOS infostealer campaign that tricks users into pasting malicious terminal commands via fake verification pages (paste-and-run/ClickFix technique) to install modular stealers and a persistent GSocket-based backdoor; it harvests macOS credentials, Keychain items, browser passwords, and cryptocurrency wallet data and exfiltrates results via Telegram bots and compromised domains, with Group-IB telemetry linking activity since May 2026 to at least ~100 victims across 33 countries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
