ClickLock Stealer Freezes Macs for Passwords

Malwarebytes · High sophistication
Last updated July 30, 2026

Researchers found a new macOS infostealer, “ClickLock Stealer,” that uses ClickFix-style fake verification pages to trick people into running Terminal commands. After infection, it shows a realistic macOS password prompt and can effectively lock the Mac until the victim enters the correct password, then sends stolen data to attackers via Telegram while leaving a persistent backdoor behind.

How the Attack Worked

ClickLock Stealer begins with a phishing page styled to look like a Cloudflare verification check or another common system utility. Instead of a normal captcha, the page instructs the victim to open Terminal, paste a command, and press Return, framing this as a required verification step. Once the command runs, the malware displays a convincing fake macOS password prompt that uses the victim's real username, making the request look legitimate.

Why It Succeeded

The attack blends a familiar web pattern, a browser verification screen, with a native macOS interface element that people are conditioned to trust. If the victim hesitates or refuses to enter their password, the malware triggers a kill loop that repeatedly shuts down key processes such as Finder, Dock, browsers, and System Settings every 210 milliseconds, for up to 83 hours or until the correct password is entered. This effectively forces compliance by making the computer unusable except for the password dialog.

What to Watch For

  • Any webpage asking you to open Terminal and paste a command as part of a verification process
  • Unusual progress bars or verification animations that appear designed to distract while something runs in the background
  • A macOS-style password prompt appearing shortly after following instructions from a website
  • A Mac becoming unresponsive except for a password dialog, which is not normal system behavior

Once a password is entered, it is sent along with browser, password manager, and crypto wallet data to a Telegram channel controlled by the attackers. Even if symptoms stop and some components self-delete, a persistent GSocket backdoor can remain installed, giving attackers ongoing remote access.

How to Build Resistance

Organizations should train macOS users, including executives and IT staff, to treat any request to run Terminal commands from a webpage as a major red flag rather than a routine verification step. Employees should be taught never to enter their Mac password into an unexpected prompt, especially one that follows online instructions, and instead contact IT through a known, trusted channel to verify what is happening. Awareness training should also emphasize that a computer being forced into an unusable state is a scam tactic, not a legitimate security or verification behavior, and that the absence of visible symptoms afterward does not guarantee the system is clean. This reflects techniques like T1566.002, T1204.001, and T1059.004.

Key findings

  • Delivered through ClickFix-style phishing pages that mimic Cloudflare verification or fake utilities.
  • Victims are instructed to open Terminal and paste a command as a supposed “human verification” step.
  • After execution, the malware can display a convincing fake macOS password prompt using the victim’s real username.
  • If the victim refuses to enter the password, it repeatedly kills key apps (Finder, Dock, browsers, System Settings, etc.) to make the machine unusable until compliance.
  • Stolen data (including the macOS password and browser/password manager/crypto wallet data) is sent to an attacker-controlled Telegram channel.
  • Even after some components self-delete, a persistent GSocket backdoor remains for ongoing remote access.

Who’s being targeted

  • Commonly targeted roles: All macOS users, Executives, IT / Helpdesk, Security awareness training audience.
  • Affected industries: Cross-industry (macOS users), Technology, Professional services.
  • Attack channels: website.
  • Impersonated: Cloudflare (browser verification), macOS system prompt (Apple-style password dialog).

Red flags to watch for

  • A webpage asking you to run Terminal commands as “verification”
  • Unusual “progress bar”/verification visuals used to distract while actions run
  • Instructions to copy/paste commands rather than using normal sign-in steps
  • Password prompt appears after following web instructions to run Terminal commands
  • The computer becomes unusable except for the password dialog
  • Pressure/forced compliance behavior (apps closing repeatedly) to make you enter credentials
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is ClickLock Stealer?

ClickLock Stealer is a macOS infostealer delivered through ClickFix-style phishing pages that trick users into running Terminal commands disguised as human verification.

How does ClickLock Stealer lock a Mac?

After the malicious command runs, it shows a fake macOS password prompt and, if the victim refuses to type their password, repeatedly kills key apps like Finder and Dock until the machine becomes unusable.

Where does the stolen data go?

Stolen data, including the macOS password and browser, password manager, and crypto wallet information, is sent to an attacker-controlled Telegram channel.

Does the threat end after the malware self-deletes?

No, even after some infostealer components self-delete, a persistent GSocket backdoor remains installed, giving attackers ongoing remote access.

Read the video transcript

Imagine a website that makes your Mac unusable until you type your password. That’s ClickLock Stealer. You land on a fake Cloudflare verification page. It says: open Terminal, paste this command, press Return as a 'human verification' step. That command installs ClickLock Stealer. After that, a very real-looking macOS password box pops up: 'System requires your password to continue.' If you don’t type it, ClickLock keeps killing Finder, Dock, and your browser so your Mac feels frozen. Here’s the move: if any webpage tells you to open Terminal and run a command for 'verification' or a quick fix, stop immediately and report it to IT.

Similar attacks

ClickLock Tricks Mac Users Into Running Malware

ClickLock Tricks Mac Users Into Running Malware

A macOS info-stealing malware called ClickLock Stealer uses a fake “Cloudflare verification” page to trick users into copying and running a Terminal command. It then steals browser, crypto wallet, and Keychain data and sends it to attackers via a Telegram bot, while killing processes to hide…

July 16, 2026
ClickLock Tricks Mac Users Into Pasting Malware

ClickLock Tricks Mac Users Into Pasting Malware

Researchers documented a real macOS data-stealing campaign that relies on social engineering instead of software bugs. Victims are sent to a fake “verification” page that tells them to copy and paste a command into Terminal, which silently installs a stealer and then pressures them to enter their…

July 16, 2026
ClickLock macOS Stealer Forces Password via Kill Loops

ClickLock macOS Stealer Forces Password via Kill Loops

Researchers observed a real macOS information-stealing campaign that tricks victims into pasting a command into Terminal from a “ClickFix” web page. After running, the malware shows a fake macOS password prompt and can repeatedly crash key apps (Finder/Dock/browsers) for hours or days to pressure…

July 16, 2026
“Work Panel” Streamlines Vishing Into One Console

“Work Panel” Streamlines Vishing Into One Console

Okta says it gained an inside look at “Work Panel,” a polished SaaS-style dashboard that helps voice-phishing (vishing) crews rapidly set up fake login sites and guide victims through password and MFA capture. The tool clones brand look-and-feel for services like Okta and Microsoft 365, then lets a…

July 29, 2026
Fake DocuSign Flow Tricks Users Into RMM Installs

Fake DocuSign Flow Tricks Users Into RMM Installs

Researchers found a DocuSign lookalike phishing workflow that guides people through a realistic “document viewing” experience and then convinces them to download legitimate remote access tools. Instead of classic malware, the attackers install trusted IT administration software (RMM) to keep…

July 20, 2026
Phishing Hits M365; Deepfake Vishing Targets Funds

Phishing Hits M365; Deepfake Vishing Targets Funds

The roundup describes real social-engineering incidents: a phishing email that led an employee to enter credentials on a fake Microsoft 365 login page, and a wave of voice-phishing attempts against major hedge funds using voice-mimicking technology. Both incidents show practical lures that can be…

August 7, 2026