256 Newsroom — Uganda's Digital News Infrastructure
Consumer Technology

'ClickLock' Malware Coerces Mac Users Into Giving Up Passwords - MacRumors

Share
'ClickLock' Malware Coerces Mac Users Into Giving Up Passwords - MacRumors
Image · MacRumors

What the report says

MacRumors reports that security firm Group-IB has found a new macOS threat called “ClickLock Stealer” that relies on social engineering rather than exploiting a software flaw. According to the report, the attack begins when a user is persuaded to paste and run a command in Terminal. Group-IB did not directly see the lure, but said the script’s behavior suggests it may be delivered through a fake “ClickFix” page imitating a Cloudflare or browser verification check.

Once running, the malware downloads additional components and displays a terminal animation resembling a Cloudflare progress indicator. If the user rejects the first password request, the malware reportedly makes the Mac difficult to use by repeatedly closing visible apps while the prompt remains active. MacRumors, citing Group-IB, says another process suppresses macOS security notifications for about six hours.

If the victim enters the login password, the malware then pushes a real macOS prompt asking for access to a Keychain item. Approval can expose Chrome’s “Safe Storage” encryption key, which helps protect saved browser passwords and cookies. The malware can then collect browser credentials, Keychain information, password manager vaults and cryptocurrency wallet data, sending the material to a Telegram bot. It also installs a hidden backdoor disguised as an iCloud process, according to the report.

Group-IB says the campaign has been active since May 2026 and has affected at least 100 people in 33 countries, with more than half in Europe. MacRumors notes Apple has added a macOS Tahoe 26.4 safeguard that warns users before Terminal commands copied from websites, chats or messages are pasted, and can block known malicious commands outright.

Read the full report at MacRumors →

Loading debate for this article…

Other publishers covering this story

No additional verified coverage is currently clustered with this report.

Related reporting