Bitcoin Forum
July 20, 2026, 03:26:50 PM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: ClickLock Stealer: Another crypto stealer malware on MacOS  (Read 40 times)
SatsPH (OP)
Member
**
Offline

Activity: 111
Merit: 69

For JM


View Profile
July 17, 2026, 10:49:19 AM
 #1

Another MacOS malware is in the wild, dubbed ClickLock as it combines ClickFix + Locker technique. This malware will forced you to enter your login password as it will terminate all visible processes.

And it targets the following:

  • 8 web browsers
  • 31 cryptocurrency wallet browser extensions
  • 7 password manager extensions
  • 8 desktop cryptocurrency wallet applications
  • Blockchain addresses across 6 different networks
  • macOS Keychain
  • Shell history
  • FTP credentials

And base on their findings, their lure their victims thru ClickFix, that trigger a fake Cloudflare “human verification” sequence with an animated progress bar. And then after that, keyboard are being disabled and the malware modules are being downloaded from the background.



After the module has been executed, it will display a fake password dialog box. And if the users enters his data, exfiltrates it to the attacker via Telegram.

So again, with this recent spat of attacks on MacOS users, we need to be very vigilant time and time again.



https://www.group-ib.com/blog/clicklock-stealer-macos-malware/


joniboini
Legendary
*
Offline

Activity: 2982
Merit: 1910



View Profile WWW
July 18, 2026, 02:22:39 PM
 #2

So again, with this recent spat of attacks on MacOS users, we need to be very vigilant time and time again.
I assume this means the userbase of MacOS is getting bigger, or attackers believe they have a higher chance of having a decent stock of crypto or other assets when they use MacOS. I remember reading another report about MacOS malware just a few days ago.

This new malware seems to be a month old, judging from when it was first discovered. Looks like their script managed to fool quick scanner like VirusTotal if I'm reading correctly. I wonder if their existing model doesn't share any similarity with previous malwares on their database or if there is other reasons for that.

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
████████████████████████
████████▄▄██████▄▄██████

████████████████████████
██▄▄█████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
██████▀▀██████▀▀████████
████████████████████████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
█████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀
▄██▀▄██
█████▀▀
███████
████████
▀██▄████
▄████▄▄
▄█████▀███
▄█████▀████
█████▀███████
▀██▀█████████
|  BTC     XMR  
  DAI     LTC  
   Fees  0.8%    
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!