ClickLock Malware Locks Mac with Fake Password Prompts, Steals User Data
> cd .. / HUB_EDITORIALE
News

ClickLock Malware Locks Mac with Fake Password Prompts, Steals User Data

[2026-07-20] Author: Meteora Web Redazione
> share
Zenithby Meteora Web The operating system for your business. Social, clients, bookings and invoices in one platform. Gyms, barbers, professionals. Discover Zenith Free demo · no card

A new macOS malware named ClickLock Stealer is coercing users into surrendering their passwords through a barrage of fake system prompts. Discovered by security firm Group-IB, the malware requires no exploits or elevated privileges; it relies on tricking victims into pasting a command into Terminal. Once run, the script locks the system progressively, displaying password dialogs until the user gives in. Stolen data includes browser credentials, Keychain items, password manager vaults, and cryptocurrency wallets. The campaign has been active since May 2026, with over 100 victims across 33 countries, more than half in Europe.

ClickLock Stealer in action: no exploit needed, just a Terminal command

Group-IB did not directly observe how victims are lured into pasting the command, but the method is clear. The malware is delivered via a fake ClickFix page posing as a Cloudflare check or browser verification step. The page instructs visitors to copy and paste a command into Terminal as a supposed verification requirement. Once executed, the script discreetly downloads modules and shows a loading animation mimicking Cloudflare. If the user declines the initial password dialog, the malware begins locking system usage: it kills every visible app every 210 milliseconds, making the desktop unusable until the password is entered. Another loop suppresses macOS security notifications for about six hours, keeping the victim unaware.

Sponsored Protocol

How the fake ClickFix page tricks victims and steals encryption keys

If the victim gives in and enters their password, a second genuine macOS prompt appears, asking to allow access to a Keychain item. Granting it hands over Chrome's Safe Storage AES key, which the browser uses to encrypt saved passwords and cookies. With both the login password and the encryption key, ClickLock harvests browser credentials, Keychain data, password manager vaults, and cryptocurrency wallets, then sends everything to a Telegram bot. It also installs a hidden backdoor disguised as an iCloud process for persistent access. The campaign has predominantly targeted Europe, with over half the victims in the region.

Sponsored Protocol

Apple's and Opera's countermeasures: block pasted commands in Terminal

Apple has updated macOS to defend against this class of attack. macOS Tahoe 26.4 adds a warning when the user attempts to paste a command into Terminal from a website, chat, or message; the paste is blocked until the user reviews it. If the system detects known malware, the paste is blocked outright with no override. Opera browser has also introduced a similar feature. It goes without saying that no legitimate website will ever ask users to paste commands into Terminal. For more on cybersecurity threats, check our article on US military apps containing Chinese and Russian code, a case highlighting the spread of unsafe code. For a broader overview, see the Wikipedia page on malware.

Sponsored Protocol

Source: https://www.macrumors.com/2026/07/20/clicklock-malware-mac-users-giving-up-passwords

> share
Meteora Web Redazione

> AUTHOR_EXTRACTED

Meteora Web Redazione

La redazione di Meteora Web Agency: ingegneri informatici e professionisti del digitale che pubblicano ogni giorno news e approfondimenti su tecnologia, software, marketing e innovazione.
[ Read Full Dossier ]

> METEORA_WEB // DIGITAL AGENCY

We build the digital presence your business deserves.

Websites, social media, online advertising, e-commerce and high-performance hosting, engineered with method by computer engineers in Sciacca, for all of Italy.

> MW_JOURNAL

> READ_ALL()