Security firm Group-IB has uncovered ClickLock Stealer, a new Mac threat that hijacks normal system behavior to pressure victims into handing over passwords and access.
ClickLock Stealer
ClickLock StealerThe firm said the campaign has reached at least 100 targets in 33 countries since May 2026, with more than half of the identified activity in Europe. Group-IB also found targets in North America, the Middle East and Africa.
ClickLock builds on ClickFix, a familiar scam that uses fake CAPTCHA or Cloudflare verification pages to convince people to paste commands into Terminal. ClickLock adds a coercive step when a victim cancels a password prompt or refuses access.
The attack begins only after the victim copies a command from a malicious page and runs it in Terminal. The script then downloads separate components designed to steal passwords, collect browser and cryptocurrency data, access the macOS Keychain and install a persistent backdoor.