logo

New ClickLock Stealer locks your Mac until you hand over your password

ID: c3288c55-4137-5398-99f2-2c1590fb4022

STIX ID: report--c3288c55-4137-5398-99f2-2c1590fb4022

Feed Name: Malwarebytes Blog

Threat Score
78/100

Date Published: 2026-07-21

Date Updated: 2026-07-21

...
...

ClickLock Stealer is a modular macOS infostealer distributed via fake Cloudflare/utility phishing pages that trick victims into running Terminal commands; it harvests browser credentials, password manager and crypto wallet data, coerces users into revealing their macOS password via a persistent fake prompt and kill-loop, exfiltrates data to a Telegram channel, and leaves a GSocket backdoor for ongoing access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.