Get free scan and check if your device is infected.
Remove it nowTo use full-featured product, you have to purchase a license for Combo Cleaner. Seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
What kind of malware is ClickLock Stealer?
ClickLock Stealer is a modular information stealer targeting macOS users. According to research published by Group-IB, it was discovered in June 2026 with zero initial detections on VirusTotal. Cybercriminals distribute it via ClickFix, tricking users into running a Terminal command that silently installs the malware.
Once active, ClickLock Stealer harvests passwords, browser data, Keychain entries, and cryptocurrency wallet data. It also deploys a backdoor that gives attackers persistent remote access to the infected Mac. If ClickLock Stealer is detected on a device, it should be removed as soon as possible.

ClickLock Stealer overview
ClickLock Stealer is built around a modular architecture. An orchestrator script, delivered via a fake verification page, downloads four separate components onto the Mac. Each module handles a different theft task, and the modular design makes the malware adaptable and harder to detect because each piece can be updated independently.
The malware targets eight browsers: Chrome, Brave, Edge, Opera, Vivaldi, Arc, Chromium, and Firefox. From each, it collects saved login credentials, cookies, browsing history, bookmarks, and autofill data. It also extracts the Chrome Safe Storage key from the macOS Keychain, which it uses to decrypt locally stored browser passwords.
Cryptocurrency is a primary focus. ClickLock Stealer targets over 30 browser-based wallet extensions, including MetaMask, Phantom, Coinbase Wallet, Trust Wallet, Rabby, and OKX Wallet, across Chromium browsers and Firefox. Eight desktop wallet applications are also in scope, including Exodus, Atomic Wallet, Bitcoin Core, Electrum, Coinomi, and Wasabi Wallet.
Additional capabilities
Password manager extensions are also targeted. ClickLock Stealer collects data from Bitwarden, LastPass, 1Password, NordPass, Keeper, Dashlane, and Talisman. Shell history files, FileZilla credentials, and SSH key files are collected alongside basic system information: username, macOS version, CPU model, RAM, disk size, and the device's public IP address.
One component installs a backdoor based on the open-source GSocket tool. It runs under the name iCloud inside the user's Library folder and establishes a reverse shell to the attackers' server. Three persistence mechanisms keep it running after reboots: a LaunchAgent, a crontab entry, and a shell RC file modification. Unlike other modules, this component does not delete itself.
ClickLock Stealer takes active steps to avoid detection. It hides the Terminal cursor, suppresses macOS security alerts by repeatedly terminating NotificationCenter for hours, and disguises payload download commands within random-looking text. Several payloads are piped directly into bash without touching the disk. Most modules self-delete after completing their tasks.
| Name | ClickLock malware |
| Threat Type | Stealer, Mac malware, Mac virus, password-stealing virus. |
| Detection Names | Avast (MacOS:Downloader-HT [Drp]), Combo Cleaner (Trojan.MAC.Downloader.52), ESET-NOD32 (OSX/TrojanDownloader.Agent.CY Trojan), Kaspersky (Trojan-PSW.Shell.Agent.i), Symantec (Trojan Horse), Full List (VirusTotal) |
| Symptoms | Stealers are designed to stealthily infiltrate the victim's computer and remain silent, and thus no particular symptoms are clearly visible on an infected machine. |
| Distribution Methods | ClickFix, social engineering |
| Damage | Stolen passwords and banking information, identity theft, monetary loss, account hijacking, possible additional infections. |
| Malware Removal (Windows) |
To eliminate possible malware infections, scan your computer with legitimate antivirus software. Our security researchers recommend using Combo Cleaner. Download Combo CleanerTo use full-featured product, you have to purchase a license for Combo Cleaner. 7 days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com. |
Conclusion
ClickLock Stealer is a serious threat because it targets passwords, wallets, and Keychain data simultaneously while actively suppressing security alerts that might reveal its presence. Its persistent GSocket backdoor means attackers can maintain access even after the stealer modules finish running.
Group-IB identified over 100 victims across 33 countries, with more than half located in Europe. The campaign appears financially motivated, focused on high-income regions where macOS and cryptocurrency use are both common. If there is reason to believe a Mac is infected, removal should be treated as urgent.
More examples of malware targeting macOS are ShadeStager, PamStealer, and Infiniti.
How did ClickLock Stealer infiltrate my device?
ClickLock Stealer spreads through a social engineering technique known as ClickFix. Users are directed to fake verification pages, often mimicking Cloudflare CAPTCHA screens, that instruct them to open Terminal and paste a command. Executing that command begins the infection chain, silently downloading the malware's components onto the Mac.
The ClickFix lures observed in this campaign take several forms. Some impersonate Cloudflare security checks; others disguise themselves as legitimate software documentation or Apple community posts suggesting Mac maintenance steps. In each case, the goal is to persuade the user to run a Terminal command they believe is harmless.
Payloads are served from compromised WordPress websites. Once the orchestrator script runs, it downloads each of ClickLock Stealer's modules and immediately begins requesting system-level permissions, including Full Disk Access. The malware walks victims through granting this permission step by step, opening System Settings directly to the relevant panel.
How to avoid malware?
Be cautious about any website, pop-up, or online post that asks you to paste commands into Terminal, even if the page appears to come from a legitimate source such as a CAPTCHA prompt, a software installer, or a tech-support resource. No genuine verification or update process requires this. Treat any such instruction as a red flag.
Download software only from the Mac App Store or official developer websites. Avoid pirated software and keep macOS and installed applications updated. If your computer is already infected, we recommend running a scan with Combo Cleaner Antivirus for Windows to automatically eliminate all threats.
ClickFix lures used to distribute ClickLock Stealer (source: group-ib.com):
Instant automatic malware removal:
Manual threat removal might be a lengthy and complicated process that requires advanced IT skills. Combo Cleaner is a professional automatic malware removal tool that is recommended to get rid of malware. Download it by clicking the button below:
DOWNLOAD Combo CleanerBy downloading any software listed on this website you agree to our Privacy Policy and Terms of Use. To use full-featured product, you have to purchase a license for Combo Cleaner. 7 days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Quick menu:
Potentially unwanted applications removal:
Remove potentially unwanted applications from your "Applications" folder:

Click the Finder icon. In the Finder window, select "Applications". In the applications folder, look for "MPlayerX","NicePlayer", or other suspicious applications and drag them to the Trash. After removing the potentially unwanted application(s) that cause online ads, scan your Mac for any remaining unwanted components.
DOWNLOAD remover for malware infections
Combo Cleaner checks if your computer is infected with malware. To use full-featured product, you have to purchase a license for Combo Cleaner. 7 days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Frequently Asked Questions (FAQ)
My device is infected with ClickLock Stealer malware, should I format my storage device to get rid of it?
Formatting will remove ClickLock Stealer, but it will also erase all data stored on the device. Before taking such a drastic step, it is generally better to first try a reputable security tool like Combo Cleaner.
What are the biggest issues that ClickLock Stealer malware can cause?
ClickLock Stealer can drain cryptocurrency wallets, expose saved passwords, compromise Keychain data, and give attackers persistent remote access via its GSocket backdoor. This can result in financial loss, identity theft, and account takeover.
What is the purpose of ClickLock Stealer malware?
ClickLock Stealer is designed to steal sensitive data, primarily cryptocurrency wallet contents, browser credentials, and Keychain entries. It also installs a persistent backdoor so attackers retain access to the infected Mac after the initial theft.
How did ClickLock Stealer malware infiltrate my computer?
ClickLock Stealer is distributed via ClickFix. A user is redirected to a fake verification page and told to paste a command into Terminal. Running that command downloads and installs the malware on the Mac.
Will Combo Cleaner protect me from malware?
Yes, Combo Cleaner can detect and remove most threats. However, more advanced threats can be well hidden in the system, so it is important to run a full scan to ensure complete elimination.
Share:
Tomas Meskauskas
Expert security researcher, professional malware analyst
I am passionate about computer security and technology. I have an experience of over 10 years working in various companies related to computer technical issue solving and Internet security. I have been working as an author and editor for pcrisk.com since 2010. Follow me on Twitter and LinkedIn to stay informed about the latest online security threats.
PCrisk security portal is brought by a company RCS LT.
Joined forces of security researchers help educate computer users about the latest online security threats. More information about the company RCS LT.
Our malware removal guides are free. However, if you want to support us you can send us a donation.
DonatePCrisk security portal is brought by a company RCS LT.
Joined forces of security researchers help educate computer users about the latest online security threats. More information about the company RCS LT.
Our malware removal guides are free. However, if you want to support us you can send us a donation.
Donate



▼ Show Discussion