Also known as: tracked as, CVE-2026-0257, lets attackers
A new modular macOS information stealer named ClickLock Stealer has been discovered targeting users primarily in Europe, North America, and the Middle East. The malware is likely distributed via ClickFix social engineering pages that trick victims into pasting malicious commands into Terminal. Once executed, it deploys four components: a credential stealer, a Keychain stealer targeting Chrome's encryption key, a comprehensive crypto wallet harvester, and a persistent GSocket-based backdoor. The malware employs an aggressive 'locker' technique, killing all visible applications except password dialogs to force user compliance. It targets data from eight browsers, 31 crypto wallet extensions, seven password managers, desktop wallets, macOS Keychain, and shell history. The campaign has compromised at least 100 victims across 33 countries since May 2026, using compromised WordPress domains and Telegram for command and control and exfiltration.
Targeted Sectors
Executive Summary
ClickLock Dev is a sophisticated threat actor operating since May 2026, targeting macOS users primarily in Europe, North America, and the Middle East. Their primary tool, ClickLock Stealer, is a modular malware designed to steal sensitive information such as credentials, crypto assets, and system configurations. The group employs advanced techniques including social engineering via malicious Terminal commands and leverages compromised infrastructure for command and control.
Goals & Targeting
ClickLock Dev targets users across Europe, North America, and the Middle East due to these regions' high adoption of cryptocurrency and macOS systems. Their strategic objectives are centered on financial gain through stealing sensitive data such as加密钱包信息、credential访问凭据和系统配置数据。 They focus on individual users, particularly those with access to valuable digital assets, indicating a clear intent to exploit financial opportunities.
Enhanced Description
ClickLock Dev operates with high sophistication, deploying the ClickLock Stealer malware to target macOS users. This malware extracts credentials, Keychain data, crypto wallet contents, and more, using a combination of social engineering and technical exploitation. The threat actor's primary vector involves tricking users into executing malicious commands via fake ClickFix pages. Their infrastructure uses compromised domains and Telegram for command and control (C2) and exfiltration. ClickLock Dev's modular approach and focus on financial gain highlight their capability to adapt and remain undetected, posing a significant risk to individuals with high-value digital assets.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
ClickLock Dev's campaign has compromised at least 100 victims across 33 countries. They utilize social engineering through malicious Terminal commands and legitimate-looking domains for C2, indicating a persistent and evolving threat. Their reliance on macOS targets suggests a focus on niches with higher perceived profitability.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate confidence in ClickLock Dev's details due to new discovery and limited historical data. Gaps exist in long-term activity patterns and complete capability set.
No campaigns linked yet.
No observed data linked yet.
40
Techniques
30
Tools
0
Campaigns
40
IOCs
0
Observed Data
8
Tactics