ClickLock malware on macOS forces users to enter passwords
- Evelyn Carter

- Jul 22
- 4 min read
ClickLock Stealer is an information-stealing malware targeting macOS that was disclosed by Group-IB on July 16, 2026. The campaign was observed on at least 100 devices across 33 countries. ClickLock does not exploit software vulnerabilities. Instead, it tricks users into pasting commands into Terminal, then repeatedly closes applications and displays a system password prompt.
The risk extends beyond a single login account. The malware also targets browser data, password managers, cryptocurrency wallets, Terminal history, and authentication data stored on the device. For businesses that use Macs for work, one infected device could become an entry point for account takeover, SaaS access, or deeper compromise of internal systems.
What Happened to macOS users?
ClickLock Stealer is a malicious shell script discovered by Group-IB after a sample was uploaded to VirusTotal on June 9, 2026. Infrastructure indicators suggest that the campaign may have been active since late May 2026 and affected at least 100 systems across 33 countries, with more than half of the affected countries located in Europe.

The infection chain likely begins with the ClickFix technique. This method tricks users into copying and running a command under the pretext of fixing an error, verifying an account, or completing a “not a robot” check.
ClickLock also temporarily disables macOS NotificationCenter for approximately six hours. The objective is to limit notifications that could alert the victim to suspicious activity.
How does ClickLock force victims to provide their passwords?
ClickLock uses coercive loops instead of exploiting elevated privileges. Initially, the malware creates a fake macOS password dialog using osascript, displaying the victim’s actual username together with an externally downloaded Apple icon.
If the victim enters a password, the script verifies the credentials and sends the data to the attacker via Telegram. If the user closes the dialog, ClickLock creates two LaunchAgents named com.authirity.plist and com.chromer.plist so that it can run again the next time the user logs in.
Contrary to the belief that Macs are less likely to be targeted by malware, ClickLock shows that the value of data stored on macOS is making the platform an increasingly attractive target. Businesses can refer to the analysis of common misconceptions about macOS and Linux security to reassess the assumptions used in their endpoint security policies.
What data can ClickLock steal?
ClickLock’s data-harvesting module targets eight browsers: Google Chrome, Mozilla Firefox, Brave, Microsoft Edge, Opera, Vivaldi, Arc, and Chromium. The targeted data includes login credentials, cookies, autofill data, bookmarks, local storage, and session storage.
The malware also collects:
Cryptocurrency wallet extensions and desktop wallet files.
Encrypted wallet vaults for potential offline cracking.
Data from password manager extensions.
Cryptocurrency addresses associated with EVM, Bitcoin, Solana, TRON, TON, and Stacks.
Shell command history.
FileZilla configuration and recently accessed server lists.
Basic device information and the public IP address.
Who is most at risk?
macOS users who frequently install development tools, download software outside the App Store, or follow technical instructions on websites face a higher risk. These users may view a request to open Terminal as a normal troubleshooting step.
In business environments, the risk is particularly significant for:
Developers with access to source code, Git tokens, and cloud infrastructure.
Finance employees or digital asset managers.
System administrators using privileged accounts.
Employees who access multiple SaaS services through a browser.
Personal Mac devices used for work but not centrally managed.
Apple recommends that users be cautious about instructions that ask them to run commands, download software only from the App Store or the developer’s official website, and review privacy settings and application control permissions under Privacy & Security.
What should businesses do immediately if they suspect an infection?
The first priority is to isolate the device, invalidate related login sessions, and preserve evidence. Users should not continue entering passwords into repeated dialog boxes or attempt to keep using the device for business operations.
Businesses can refer to IPSIP’s Cybersecurity Training and Consulting program to build exercises that help employees recognize social engineering, phishing, and ClickFix scenarios that closely reflect real workplace conditions.
What does the expert perspective from IPSIP Vietnam show?
ClickLock uses ClickFix to turn the user into the execution mechanism. The malware then combines fake dialog boxes, legitimate Keychain prompts, and process-termination loops to apply psychological pressure.
Potential damage includes account loss, SaaS session hijacking, browser data exposure, cryptocurrency theft, operational disruption, and prolonged unauthorized access through a backdoor.
Mac devices need to be managed as full enterprise endpoints rather than treated as inherently secure. Security policies should combine device management, behavioral monitoring, and employee training.
Which IPSIP Vietnam Solutions Are Suitable for Businesses?
Cybersecurity training addresses the campaign’s direct cause: users are tricked into executing commands themselves. Training content should simulate fake CAPTCHA pages, ClickFix prompts, password dialogs, and incident reporting procedures. Businesses can review the scope of IPSIP’s Cybersecurity Training and Consulting services.

SOC 24/7 is suitable for monitoring signals such as abnormal process termination, mass access to browser profile directories, and data transmission to Telegram. IPSIP discusses a combined monitoring and technical assessment model in its article on optimizing cybersecurity budgets with SOC and Pentest.
References










Comments