
ClickLock Tricks Mac Users Into Running Malware
A macOS info-stealing malware called ClickLock Stealer uses a fake “Cloudflare verification” page to trick users into copying and running a Terminal command.…
Researchers documented a real macOS data-stealing campaign that relies on social engineering instead of software bugs. Victims are sent to a fake “verification” page that tells them to copy and paste a command into Terminal, which silently installs a stealer and then pressures them to enter their Mac password to complete the theft.
ClickLock is a real macOS data-stealing campaign that skips software exploits entirely and instead relies on convincing a user to do the damage themselves. Victims are directed to a fake verification page, styled to resemble a Cloudflare check, that instructs them to copy a command and paste it into the macOS Terminal app. This is the ClickFix technique: rather than exploiting a vulnerability, the attacker gets the user to run the malicious code voluntarily. Once pasted, the command silently installs the ClickLock stealer while the page displays a fake progress animation to keep the victim distracted and reassured that a legitimate check is underway.
The entire attack chain depends on a single moment of trust: the user pasting a command into Terminal without questioning why a website would ever need that level of access to their computer. Terminal is unfamiliar territory for many users, so a confident-looking prompt claiming to "verify" the machine can override normal caution. The payloads are hosted on compromised WordPress sites and command-and-control runs through Telegram, which lets the operation blend into ordinary web and messaging traffic rather than triggering obvious alarms.
Once the command runs, ClickLock goes after browser data, crypto wallet extensions and apps, password manager extensions, the macOS Keychain, shell history, FTP credentials, and blockchain addresses. It then prompts for the macOS password directly; if the victim refuses, it repeatedly kills visible applications to force compliance until the theft can complete quietly.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
ClickLock is a macOS data-stealing campaign that relies on social engineering rather than software exploits, using the ClickFix technique to get victims to paste a command into Terminal.
Victims land on a fake Cloudflare-style verification page that instructs them to copy and paste a command into Terminal, which silently installs the stealer while a fake progress animation plays.
After infection, the malware prompts for the Mac login password to complete the theft, and if the victim refuses it repeatedly closes visible applications until they comply.
It targets browser data, crypto wallet extensions and apps, password manager extensions, macOS Keychain, shell history, FTP credentials, and blockchain addresses.
You’re on a website, it says: “Cloudflare needs a manual check, copy this into Terminal to continue.” Stop right there. This is the ClickLock Stealer using a ClickFix trick. After you paste that command, it silently installs, shows a fake Cloudflare progress animation, and starts hunting your browser data, crypto wallets, password managers, even your macOS Keychain. Then comes the shove: a macOS password prompt pops up during this web “verification.” If you don’t enter it, apps keep force-closing until you give in, and the theft finishes quietly. Remember this: a website that tells you to paste a command into Terminal is almost always a scam. Close the tab immediately and report it to IT.

A macOS info-stealing malware called ClickLock Stealer uses a fake “Cloudflare verification” page to trick users into copying and running a Terminal command.…

Researchers observed a real macOS information-stealing campaign that tricks victims into pasting a command into Terminal from a “ClickFix” web page. After…

Researchers found a new macOS infostealer, “ClickLock Stealer,” that uses ClickFix-style fake verification pages to trick people into running Terminal…

Researchers report an active phishing-as-a-service operation, Forg365, that targets Microsoft 365 users with document/payment-themed lures and techniques that…

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…

Researchers observed LogoKit phishing campaigns that create a unique fake login page for each recipient in real time. The kit pulls a live screenshot of the…