logo

ClickLock Stealer: Paste Once, Lose Everything

ID: dd09c55f-dd41-5f29-adb3-88dfa940fbae

STIX ID: report--dd09c55f-dd41-5f29-adb3-88dfa940fbae

Feed Name: Group-IB Blog

Threat Score
78/100

Date Published: 2026-07-16

Date Updated: 2026-07-16

...
...

## Executive summary Group-IB reports on 'ClickLock Stealer', a newly observed modular macOS infostealer that leverages ClickFix paste-based social engineering to coerce users into granting credentials and Keychain access, harvests browser/password manager/desktop wallet data (including Chrome Safe Storage key and multiple crypto wallet extensions), and installs a persistent GSocket-based backdoor; components exfiltrate data via Telegram and compromised WordPress domains, the operation targeted ~100 victims in 33 countries and employed anti-forensic timestomping and self-deletion to evade detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.