New ClickLock macOS Malware Tricks Users Into Revealing Login Passwords

Security researchers have identified a new macOS information-stealing malware dubbed ClickLock that forces victims to enter their system login password by repeatedly killing all visible processes on the infected machine.

According to cybersecurity firm Group-IB, which discovered the threat, ClickLock terminates every running application and process visible to the user, leaving them unable to interact with their computer until they enter their credentials through a fake system prompt. Once the password is submitted, the malware gains full access to the users macOS account.

The attack begins when a user is tricked into copying and pasting a malicious command into the macOS Terminal application. This is typically achieved through social engineering tactics, such as fake tech support calls, phishing emails, or fraudulent websites that claim the user needs to run a command to fix a security issue or install necessary software.

After execution, ClickLock establishes persistence on the system by creating launch agents that ensure it runs automatically after each reboot. Beyond stealing login credentials, the malware can extract browser cookies, saved passwords from password managers, cryptocurrency wallet files, Telegram Desktop session data, and other sensitive documents stored on the device.

Group-IB reported that victims have been identified across 33 countries since ClickLock began spreading in May 2026. The malware represents a growing trend of macOS-targeted threats that bypass traditional security measures by relying on user interaction rather than exploiting technical vulnerabilities.

Users are advised to never paste unknown commands into the Terminal application, even if prompted by messages that appear to come from legitimate sources. The safest approach is to verify any technical support claim independently by contacting the organization directly through official channels.

This article was adapted from Bleeping Computer. Read the original here.