Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors clicklock dev

Also known as: tracked as, CVE-2026-0257, lets attackers

Description

A new modular macOS information stealer named ClickLock Stealer has been discovered targeting users primarily in Europe, North America, and the Middle East. The malware is likely distributed via ClickFix social engineering pages that trick victims into pasting malicious commands into Terminal. Once executed, it deploys four components: a credential stealer, a Keychain stealer targeting Chrome's encryption key, a comprehensive crypto wallet harvester, and a persistent GSocket-based backdoor. The malware employs an aggressive 'locker' technique, killing all visible applications except password dialogs to force user compliance. It targets data from eight browsers, 31 crypto wallet extensions, seven password managers, desktop wallets, macOS Keychain, and shell history. The campaign has compromised at least 100 victims across 33 countries since May 2026, using compromised WordPress domains and Telegram for command and control and exfiltration.

Goals & Targeting

Targeted Sectors

Financial services
Media
Manufacturing
Defense

AI Analysis

· 1 week ago

Executive Summary

ClickLock Dev is a sophisticated threat actor operating since May 2026, targeting macOS users primarily in Europe, North America, and the Middle East. Their primary tool, ClickLock Stealer, is a modular malware designed to steal sensitive information such as credentials, crypto assets, and system configurations. The group employs advanced techniques including social engineering via malicious Terminal commands and leverages compromised infrastructure for command and control.

Goals & Targeting

ClickLock Dev targets users across Europe, North America, and the Middle East due to these regions' high adoption of cryptocurrency and macOS systems. Their strategic objectives are centered on financial gain through stealing sensitive data such as加密钱包信息、credential访问凭据和系统配置数据。 They focus on individual users, particularly those with access to valuable digital assets, indicating a clear intent to exploit financial opportunities.

Enhanced Description

ClickLock Dev operates with high sophistication, deploying the ClickLock Stealer malware to target macOS users. This malware extracts credentials, Keychain data, crypto wallet contents, and more, using a combination of social engineering and technical exploitation. The threat actor's primary vector involves tricking users into executing malicious commands via fake ClickFix pages. Their infrastructure uses compromised domains and Telegram for command and control (C2) and exfiltration. ClickLock Dev's modular approach and focus on financial gain highlight their capability to adapt and remain undetected, posing a significant risk to individuals with high-value digital assets.

Key Capabilities

  • Credential stealer targeting browser histories
  • Keychain stealer targeting Chrome encryption keys
  • Comprehensive crypto wallet harvester
  • Persistent GSocket-based backdoor
  • Locker technique to force user compliance

MITRE ATT&CK Tactics

Extraction
Persistence
Social Engineering
Credential Access

ATT&CK Techniques

T1078
T1543
T1566
T1003
T1006

Software / Tooling

ClickLock Stealer

Campaigns & Victims

ClickLock Dev's campaign has compromised at least 100 victims across 33 countries. They utilize social engineering through malicious Terminal commands and legitimate-looking domains for C2, indicating a persistent and evolving threat. Their reliance on macOS targets suggests a focus on niches with higher perceived profitability.

IOC Patterns

  • Spear-phishing via ClickFix pages instructing users to paste malicious commands in Terminal
  • Compromised WordPress domains as command-and-control infrastructure
  • GSocket-based persistence mechanisms

Recommended Actions

  • Educate users on recognizing social engineering attempts
  • Monitor network traffic for known C2 domains and suspicious activities
  • Implement endpoint detection solutions to identify malicious processes
  • Enhance macOS system hardening measures against known exploits

Suggested Tags

malware
financial-fraud
crypto-theft
macOS-specific
spear-phishing

Confidence Assessment

Moderate confidence in ClickLock Dev's details due to new discovery and limited historical data. Gaps exist in long-term activity patterns and complete capability set.

ATT&CK Techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 15 URL 5

References

  1. www.group-ib.com — Cited by web research for: T1543

Intel Summary

40

Techniques

30

Tools

0

Campaigns

40

IOCs

0

Observed Data

8

Tactics

Tags

Backdoor / C2
malware
financial-fraud
crypto-theft
macOS-specific
spear-phishing

Details

Type
Unknown
Primary Motivation
Financial gain
Confidence
55%
Added
Jul 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.