THE ClickLock Stealer is a new macOS malware identified by Group-IB, specifically targeting macOS users, especially those holding cryptocurrencies. This malware exploits social engineering rather than needing exploits or elevated privileges. It operates via a fake Cloudflare CAPTCHA to trick users into entering their passwords after locking their desktops. Group-IB reports at least 100 victims across 33 countries since May 2026.
Key capabilities include theft of passwords, crypto wallets, and installation of a GSocket backdoor. The malware sends stolen data to Telegram bots and self-deletes most components to evade detection. There is currently no confirmed attribution of the attack.