The nasty new ClickLock malware won’t take no for an answer. It locks up your entire Mac screen and keeps it that way until you type in the password.
The malware already hit victims across 33 countries, and it’s not stopping. Once it gets your password, it targets your Keychain, saved logins and crypto wallets, then plants a backdoor that sticks around for good.
How ClickLock malware tricks you into pasting a command
While macOS includes strong built-in security features such as Gatekeeper and notarization, that doesn’t mean Mac users are immune to malware. Modern attacks increasingly rely on social engineering rather than software exploits, tricking people into bypassing Apple’s protections themselves. ClickLock is a perfect example.
Threat intelligence firm Group-IB first spotted the malware sitting on VirusTotal with zero detections at that time. It was dubbed ClickLock as a nod to the ClickFix scam that likely delivers it, and the “locking” trick it uses to force compliance.
As noted, ClickLock rides in on ClickFix, a scamming technique plaguing Mac users for months. It works by showing a fake webpage dressed up as a Cloudflare “verify you’re human” check and telling you to copy a command and paste it into Terminal.
And that single paste is all it takes. The command then kicks off a script that requires no exploit or admin password to run. Once triggered, the script shows a fake Cloudflare-style loading bar to keep you distracted.
In the background, it silently downloads four components: a password stealer, a Keychain stealer, a crypto wallet raider and a backdoor installer.
The loop that won’t let you escape
The script also throws up a password prompt that looks exactly like the real macOS dialog with your username and Apple logo. Enter your password, and the malware will validate it and move on. If you cancel it, the attack won’t give up. ClickLock will quietly install itself again the next time you log in.
On your next login, the malware resorts to more aggressive tactics. It kills nearly all open apps on your Mac every 210 milliseconds, with only the fake password prompt staying on the screen. Finder, Terminal, Activity Monitor, your browser — everything gets closed the moment you open it. And all of this won’t stop until you enter your password.
At the same time, another process suppresses macOS notifications for around six hours. That means you won’t get any security warning pop-ups.
Your password is just the beginning
Handing over your Mac password won’t end the attack, but just moves it forward. The malware will show a second macOS prompt, asking you to approve access to a Keychain item tied to Chrome.
Approving this means you’ve just handed over Chrome’s Safe Storage key. This is the encryption key the browser uses to protect saved passwords and cookies. Using this, attackers can decrypt your data offline, at their leisure.
ClickLock then goes on a full sweep, targeting eight different browsers, 30+ crypto wallet extensions, seven password managers and eight standalone wallets. It also grabs shell history and saved FTP logins along the way.
Everything it steals is packed in a ZIP file before the malware ships it off to a Telegram bot controlled by the attacker. Following this, most of the malware’s components are deleted, using fake file timestamps to cover their tracks.
But one piece sticks around. ClickLock installs a modified version of GSocket, an open-source tool that disguises itself as an iCloud-related process. This gives the attacker a persistent backdoor into your Mac.
Who is ClickLock targeting?
Group-IB says the campaign has been active since May 2026. While it has reached more than 100 victims across 33 countries, Europe accounts for over half of them. The rest of the attacks took place in North America, the Middle East and Africa.
The malware’s focus on crypto wallets and password managers suggests a wide net, but crypto holders seem to be the priority.
How to protect your Mac from ClickLock
Apple has already shipped a defense against this exact type of attack. macOS Tahoe 26.4 shows a warning that pops up when you paste a command into Terminal, giving you a chance to fight back.
But the protection isn’t foolproof. It currently covers only the Terminal app, not third-party alternatives, and Apple hasn’t specified exactly which commands trigger the pop-up.
Group-IB’s advice is blunt — never paste a command into Terminal because a website told you to. No legitimate process ever needs you to do so.
And if your Mac suddenly starts killing apps and showing a password prompt you didn’t ask for, don’t type anything. Instead, force a shutdown by holding the power button then boot into Safe Mode to investigate.
Your Mac’s Terminal is powerful because it trusts you completely — and ClickLock is betting that, just once, you’ll trust it back.
