
ClickLock Tricks Mac Users Into Running Malware
A macOS info-stealing malware called ClickLock Stealer uses a fake “Cloudflare verification” page to trick users into copying and running a Terminal command.…
Researchers found a new macOS infostealer, “ClickLock Stealer,” that uses ClickFix-style fake verification pages to trick people into running Terminal commands. After infection, it shows a realistic macOS password prompt and can effectively lock the Mac until the victim enters the correct password, then sends stolen data to attackers via Telegram while leaving a persistent backdoor behind.
ClickLock Stealer begins with a phishing page styled to look like a Cloudflare verification check or another common system utility. Instead of a normal captcha, the page instructs the victim to open Terminal, paste a command, and press Return, framing this as a required verification step. Once the command runs, the malware displays a convincing fake macOS password prompt that uses the victim's real username, making the request look legitimate.
The attack blends a familiar web pattern, a browser verification screen, with a native macOS interface element that people are conditioned to trust. If the victim hesitates or refuses to enter their password, the malware triggers a kill loop that repeatedly shuts down key processes such as Finder, Dock, browsers, and System Settings every 210 milliseconds, for up to 83 hours or until the correct password is entered. This effectively forces compliance by making the computer unusable except for the password dialog.
Once a password is entered, it is sent along with browser, password manager, and crypto wallet data to a Telegram channel controlled by the attackers. Even if symptoms stop and some components self-delete, a persistent GSocket backdoor can remain installed, giving attackers ongoing remote access.
Organizations should train macOS users, including executives and IT staff, to treat any request to run Terminal commands from a webpage as a major red flag rather than a routine verification step. Employees should be taught never to enter their Mac password into an unexpected prompt, especially one that follows online instructions, and instead contact IT through a known, trusted channel to verify what is happening. Awareness training should also emphasize that a computer being forced into an unusable state is a scam tactic, not a legitimate security or verification behavior, and that the absence of visible symptoms afterward does not guarantee the system is clean. This reflects techniques like T1566.002, T1204.001, and T1059.004.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
ClickLock Stealer is a macOS infostealer delivered through ClickFix-style phishing pages that trick users into running Terminal commands disguised as human verification.
After the malicious command runs, it shows a fake macOS password prompt and, if the victim refuses to type their password, repeatedly kills key apps like Finder and Dock until the machine becomes unusable.
Stolen data, including the macOS password and browser, password manager, and crypto wallet information, is sent to an attacker-controlled Telegram channel.
No, even after some infostealer components self-delete, a persistent GSocket backdoor remains installed, giving attackers ongoing remote access.
Imagine a website that makes your Mac unusable until you type your password. That’s ClickLock Stealer. You land on a fake Cloudflare verification page. It says: open Terminal, paste this command, press Return as a 'human verification' step. That command installs ClickLock Stealer. After that, a very real-looking macOS password box pops up: 'System requires your password to continue.' If you don’t type it, ClickLock keeps killing Finder, Dock, and your browser so your Mac feels frozen. Here’s the move: if any webpage tells you to open Terminal and run a command for 'verification' or a quick fix, stop immediately and report it to IT.

A macOS info-stealing malware called ClickLock Stealer uses a fake “Cloudflare verification” page to trick users into copying and running a Terminal command.…

Researchers documented a real macOS data-stealing campaign that relies on social engineering instead of software bugs. Victims are sent to a fake…

Researchers observed a real macOS information-stealing campaign that tricks victims into pasting a command into Terminal from a “ClickFix” web page. After…

Okta says it gained an inside look at “Work Panel,” a polished SaaS-style dashboard that helps voice-phishing (vishing) crews rapidly set up fake login sites…

Researchers found a DocuSign lookalike phishing workflow that guides people through a realistic “document viewing” experience and then convinces them to…

ClickFix is a fast-growing social engineering tactic that gets people to run malware themselves by pasting a command into Windows Run or macOS Terminal.…