logo

Hackers Use Paste-and-Run Commands to Deploy ClickLock Stealer Against Mac Users

ID: 3ee84d63-cfe1-5d91-a36c-0ab699432dee

STIX ID: report--3ee84d63-cfe1-5d91-a36c-0ab699432dee

Feed Name: GBHackers

Threat Score
72/100

Date Published: 2026-07-17

Date Updated: 2026-07-17

Author: Mayura Kathir

...
...

ClickLock Stealer is an actively observed macOS infostealer campaign that tricks users into pasting malicious terminal commands via fake verification pages (paste-and-run/ClickFix technique) to install modular stealers and a persistent GSocket-based backdoor; it harvests macOS credentials, Keychain items, browser passwords, and cryptocurrency wallet data and exfiltrates results via Telegram bots and compromised domains, with Group-IB telemetry linking activity since May 2026 to at least ~100 victims across 33 countries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.