NewsMV

ClickLock Mac malware steals crypto wallets and browser passwords across 33 countries

7/26/2026

A new macOS infostealer called ClickLock has targeted at least 100 systems across 33 countries since May, with Group-IB researchers tracing the original script to a VirusTotal upload dated June 9, 2026, that carried zero detections at the time of analysis.

The malware reaches machines through a fake browser-verification page that instructs users to paste a command into Terminal, then works in the background to harvest cryptocurrency wallet files, browser credentials and macOS Keychain data before exfiltrating everything through Telegram's Bot API.

How the infection chain works The lure follows a ClickFix pattern. A webpage presents a convincing Cloudflare verification sequence with an animated progress bar and reassuring messages about browser signal checks.

While that runs, the script disables keyboard interruptions, hides the Terminal cursor and pulls down several malicious components in the background.

Keep reading

Read the full story

Open on NewsMV