ClickLock Stealer is a new, modular macOS infostealer delivered via ClickFix-style phishing pages that can lock a victim’s Mac, steal their macOS password, browser and password manager data, cryptocurrency wallets, and then leave behind a persistent backdoor.
The malware was discovered by Group-IB researchers. They named it after the ClickFix distribution technique and its ability to lock a victim’s Mac if they don’t follow its instructions by killing all visible processes.
The researchers found a malicious shell script typically used to trick users into infecting their own device and followed the trail from there. The script first displays a fake Cloudflare progress bar, suggesting it was intended to be used as part of a fake browser verification flow.
Victims land on a phishing page that mimics Cloudflare verification or another fake system utility, similar to those used in the Infiniti Stealer campaign, and later ClickFix attacks impersonating Claude or cleanup utilities.
The page instructs the user to open Terminal, paste a command, and press Return, presenting it as a required “human verification” step or a quick fix.










