Researchers reported a new macOS infostealer dubbed ClickLock Stealer that tricks users into pasting a malicious bash command into Terminal through ClickFix-style pages masquerading as Cloudflare verification prompts. Group-IB said the malware has been active since at least late May and has targeted at least 100 users in 33 countries, with more than half of victims in Europe. Once launched, the malware downloads multiple payloads for browser credential theft, cryptocurrency wallet theft, Keychain theft, password manager and FileZilla credential collection, shell history harvesting, and backdoor installation, then exfiltrates the stolen data to a Telegram bot. Researchers also linked the campaign to LaunchAgent persistence and a backdoor called goyim derived largely from GSocket tooling.
ClickLock does not rely on a software exploit or privilege escalation; instead, it abuses user execution and suppresses defenses by repeatedly killing visible applications and NotificationCenter, sometimes every 210 milliseconds, until victims enter their macOS password and approve Keychain access. Apple separately published guidance warning that scammers increasingly use websites, chat agents, messaging platforms, and email to socially engineer Mac users into pasting unsafe Terminal commands, and said macOS may warn or block commands and scripts associated with known malware. Apple said such alerts mean the Mac has not yet been harmed and advised users not to run untrusted commands or scripts unless they fully trust the source.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Group-IB assessed that ClickLock Stealer has been active since at least late May 2026, targeting at least 100 users across 33 countries, with more than half of victims in Europe. The malware steals credentials, wallet data, and other sensitive information and exfiltrates data via a Telegram bot.
Group-IB discovered the ClickLock Stealer macOS malware family in early June 2026. The malware uses ClickFix-style social engineering to trick users into pasting a bash command into Terminal and then deploys credential theft, crypto theft, Keychain theft, and backdoor components.
SecurityWeek and The Hacker News reported technical details of the newly identified ClickLock Stealer, including its ClickFix-style lures, LaunchAgent persistence, Telegram bot exfiltration, and coercive process-killing loop that suppresses warnings and pressures victims to enter passwords. The reporting also noted the malware is still under development and uses a backdoor called goyim derived largely from GSocket tooling.
Apple published support guidance explaining macOS Terminal alerts that warn when pasted commands may be unsafe or when commands or scripts contain known malware. The notice says scammers socially engineer users into pasting malicious commands and advises users not to run untrusted Terminal content.
Group-IB said a ClickLock Stealer sample was uploaded to VirusTotal on 2026-06-09 and had zero antivirus detections at the time. This provides a specific early public artifact date for the malware's emergence.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
15 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcemacrumors.com
Open sourcexakep.ru
Open sourcecysecurity.news
Open sourcebleepingcomputer.com
Open sourcetheregister.com
Open sourcesupport.apple.com
Open sourceelastic.co
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.