Security researchers have identified a new macOS malware, dubbed ‘ClickLock Stealer,’ that employs persistent social engineering tactics to extract user passwords. Unlike traditional malware that exploits system vulnerabilities, ClickLock relies on deceiving users into executing malicious commands.
The attack initiates when users are directed to a counterfeit ‘ClickFix’ page, masquerading as a legitimate Cloudflare verification step. This page instructs users to copy and paste a command into the macOS Terminal, purportedly for verification purposes. Once executed, the command triggers a script that downloads additional malicious modules and displays a terminal-based loading animation, mimicking a browser verification process.
Upon execution, ClickLock presents a fake system password prompt. If the user dismisses this prompt, the malware escalates its tactics by continuously terminating visible applications every 210 milliseconds, rendering the system virtually unusable. This aggressive behavior persists until the user relents and enters their password. Additionally, the malware suppresses macOS security notifications for approximately six hours, further obfuscating its presence.
Once the user provides their password, ClickLock proceeds to extract sensitive information, including browser credentials, Keychain data, password manager vaults, and cryptocurrency wallets. This data is then exfiltrated via the Telegram Bot API. To maintain persistent access, the malware installs a hidden backdoor disguised as an iCloud process.
Since its emergence in May 2026, ClickLock has infected at least 100 systems across 33 countries, with a significant concentration in Europe. The malware’s reliance on social engineering rather than technical exploits underscores the evolving nature of cyber threats targeting macOS users.
In response to this threat, Apple has implemented security enhancements in macOS Tahoe 26.4. The update introduces a warning when users attempt to paste commands into Terminal from external sources, such as websites or messages. This feature prompts users to review the command before execution, and in cases where known malware is detected, the paste action is blocked outright.
The emergence of ClickLock highlights the increasing sophistication of malware targeting macOS platforms. Users are advised to exercise caution when prompted to execute commands from unverified sources and to keep their systems updated with the latest security patches. This incident serves as a reminder that social engineering remains a potent tool for cybercriminals, emphasizing the need for continuous vigilance and user education.