
ClickLock Tricks Mac Users Into Pasting Malware
Researchers documented a real macOS data-stealing campaign that relies on social engineering instead of software bugs. Victims are sent to a fake…
Researchers observed a real macOS information-stealing campaign that tricks victims into pasting a command into Terminal from a “ClickFix” web page. After running, the malware shows a fake macOS password prompt and can repeatedly crash key apps (Finder/Dock/browsers) for hours or days to pressure the victim into entering their password. Stolen data can include browser passwords/cookies, crypto wallet data, and a persistent backdoor, with exfiltration sent via Telegram bots.
This macOS campaign, tracked by Group-IB, began with a ClickFix-style lure: a webpage instructed victims to copy and paste a command into Terminal to complete a supposed verification step. Once executed, an orchestrator script hid the cursor and played a fake Cloudflare progress animation while quietly downloading four components from two compromised WordPress sites. This gave the victim a plausible, familiar-looking loading experience while the real payload was staged in the background.
After installation, a credential module displayed a fake AppleScript password dialog styled to look like a native macOS system prompt. The dialog validated any entered password locally against the directory service, so only correct passwords were forwarded to the operator. If the victim did not comply immediately, a kill loop repeatedly terminated Finder, Dock, browsers, Terminal and Activity Monitor in a tight cycle that could run for up to 83 hours, effectively making the Mac unusable until the victim gave in and typed their password.
Teams should train macOS users, especially developers and IT staff who are more comfortable using Terminal, to treat paste-and-run instructions as an automatic stop signal. If a Mac suddenly starts killing applications in a loop, the safer response is a force shutdown and a boot into Safe Mode rather than entering credentials into an untrusted dialog. Reinforcing that legitimate macOS updates and verification steps never require pasting commands into Terminal can help staff recognize and resist this specific coercion pattern before credentials or wallet data are exposed.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
It is a real information-stealing campaign that tricks macOS users into pasting a command into Terminal from a fake verification webpage, which then downloads malware, shows a fake password dialog, and can disrupt the desktop until the victim enters their password.
After the fake password prompt appears, a kill loop repeatedly terminates Finder, Dock, browsers, Terminal and Activity Monitor for up to 83 hours to pressure the victim into typing their password.
Treat it as an attack attempt and stop immediately; researchers urged users to view any such instruction as malicious, not a legitimate fix or verification step.
It targets browser passwords, cookies, Keychain and Chrome Safe Storage keys, and more than 30 crypto wallet extensions including MetaMask and Phantom, exfiltrating everything over Telegram bots.
Imagine your Mac keeps slamming Finder, Dock, and your browser shut for hours… all to bully you into typing your password. This is ClickLock on macOS. It starts with a 'ClickFix' page or email telling you: 'Copy this command into Terminal to complete verification,' then hides your cursor and shows a fake Cloudflare-style progress bar while it quietly downloads malware. Then comes the nasty part: a fake AppleScript password box that only sends correct passwords, plus a kill loop that keeps killing Finder, Dock, browsers, even Activity Monitor for up to 83 hours until you give in. From there it can grab Keychain, Chrome Safe Storage keys, and over 30 crypto wallets like MetaMask and Phantom, then ship it all out over Telegram bots. Your move: if any website tells you to paste a command into Terminal, stop right there, close the page, don’t run it, and report it to IT.

Researchers documented a real macOS data-stealing campaign that relies on social engineering instead of software bugs. Victims are sent to a fake…

Researchers found a new macOS infostealer, “ClickLock Stealer,” that uses ClickFix-style fake verification pages to trick people into running Terminal…

A macOS info-stealing malware called ClickLock Stealer uses a fake “Cloudflare verification” page to trick users into copying and running a Terminal command.…

Researchers found a macOS info‑stealing malware, CrashStealer, delivered through a signed and Apple‑notarized installer so it looks legitimate and passes…

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…

Okta says it gained an inside look at “Work Panel,” a polished SaaS-style dashboard that helps voice-phishing (vishing) crews rapidly set up fake login sites…