HeadlinesBriefing favicon HeadlinesBriefing.com

ClickLock Malware Locks Macs Until Passwords Surrendered

AppleInsider •
×

Security firm Group-IB has identified ClickLock Stealer, a new Mac malware campaign that targets users in at least 33 countries since May 2026. The malware builds upon the "Click Fix" scam, luring victims into running malicious commands in Terminal via fake verification pages.

Once executed, ClickLock Stealer downloads components to steal passwords, browser and cryptocurrency data, and macOS Keychain information, while also installing a backdoor. It doesn't encrypt files but instead creates disruptive loops, repeatedly closing essential applications like Finder and browsers, making the Mac unusable until a password is provided.

This tactic forces victims to surrender credentials or grant access, aiding in the theft of sensitive data from password managers, crypto wallets, and browsers. Group-IB advises users to be wary of verification pages asking for Terminal commands and to immediately change credentials if exposed. Shutting down the Mac instead of entering a password during such an attack is also recommended.