ClickLock Tricks Mac Users Into Pasting Malware

The Register Security · Medium sophistication
Last updated July 30, 2026

Researchers documented a real macOS data-stealing campaign that relies on social engineering instead of software bugs. Victims are sent to a fake “verification” page that tells them to copy and paste a command into Terminal, which silently installs a stealer and then pressures them to enter their Mac password to complete the theft.

How the attack worked

ClickLock is a real macOS data-stealing campaign that skips software exploits entirely and instead relies on convincing a user to do the damage themselves. Victims are directed to a fake verification page, styled to resemble a Cloudflare check, that instructs them to copy a command and paste it into the macOS Terminal app. This is the ClickFix technique: rather than exploiting a vulnerability, the attacker gets the user to run the malicious code voluntarily. Once pasted, the command silently installs the ClickLock stealer while the page displays a fake progress animation to keep the victim distracted and reassured that a legitimate check is underway.

Why it succeeded

The entire attack chain depends on a single moment of trust: the user pasting a command into Terminal without questioning why a website would ever need that level of access to their computer. Terminal is unfamiliar territory for many users, so a confident-looking prompt claiming to "verify" the machine can override normal caution. The payloads are hosted on compromised WordPress sites and command-and-control runs through Telegram, which lets the operation blend into ordinary web and messaging traffic rather than triggering obvious alarms.

What to watch for

  • A website or pop-up asking you to open Terminal and paste in a command
  • A verification screen with a progress animation while something happens "in the background"
  • An unexpected prompt for your macOS login password during a web-based verification step
  • Applications repeatedly closing or the Mac becoming unusable after refusing a password prompt

Once the command runs, ClickLock goes after browser data, crypto wallet extensions and apps, password manager extensions, the macOS Keychain, shell history, FTP credentials, and blockchain addresses. It then prompts for the macOS password directly; if the victim refuses, it repeatedly kills visible applications to force compliance until the theft can complete quietly.

How to build resistance

  • Treat any instruction to paste a command into Terminal from a website as an immediate red flag, regardless of who it claims to be from, and close the tab
  • Be suspicious of unexpected macOS password prompts, especially ones tied to a web "verification" flow, and confirm through official support channels instead
  • Escalate immediately if apps are repeatedly forced to close or a Mac becomes unusable after a verification step, since this pattern is designed to coerce credential entry
  • Reinforce in training that the whole attack chain, from initial access to full credential theft and data exfiltration, hinges on that one moment of trust when a user pastes an unfamiliar command

Key findings

  • Malware (“ClickLock Stealer”) uses the ClickFix technique to get users to paste a command into macOS Terminal, triggering infection without exploits.
  • Attackers distribute via “fake verification pages,” host payloads on compromised WordPress sites, and use Telegram for command-and-control/exfiltration.
  • After the Terminal command runs, a fake Cloudflare-style verification animation is shown while additional components are downloaded in the background.
  • The stealer targets browser data, crypto wallet extensions/apps, password manager extensions, macOS Keychain, shell history, FTP credentials, and blockchain addresses.
  • It coerces victims to enter their macOS password; if they refuse, it repeatedly kills visible applications to disrupt normal use until compliance.
  • Researchers observed activity since ~May, with at least 100 victims across 33 countries (more than half in Europe).

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, IT, Helpdesk, Finance, HR.
  • Affected industries: Cross-industry (general macOS users).
  • Attack channels: website.
  • Impersonated: Cloudflare verification page, macOS system prompt during ‘verification’.

Red flags to watch for

  • A website asks you to open Terminal and paste a command
  • Verification uses a fake progress animation while doing something ‘in the background’
  • Unexpected prompts for your macOS password during a web verification step
  • Password prompt appears during a web ‘verification’ flow
  • Applications repeatedly close if you don’t enter the password
  • System behavior feels coercive or urgent to force a password entry
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is ClickLock malware?

ClickLock is a macOS data-stealing campaign that relies on social engineering rather than software exploits, using the ClickFix technique to get victims to paste a command into Terminal.

How does ClickLock infect a Mac?

Victims land on a fake Cloudflare-style verification page that instructs them to copy and paste a command into Terminal, which silently installs the stealer while a fake progress animation plays.

Why does ClickLock ask for a macOS password?

After infection, the malware prompts for the Mac login password to complete the theft, and if the victim refuses it repeatedly closes visible applications until they comply.

What data does ClickLock target?

It targets browser data, crypto wallet extensions and apps, password manager extensions, macOS Keychain, shell history, FTP credentials, and blockchain addresses.

Read the video transcript

You’re on a website, it says: “Cloudflare needs a manual check, copy this into Terminal to continue.” Stop right there. This is the ClickLock Stealer using a ClickFix trick. After you paste that command, it silently installs, shows a fake Cloudflare progress animation, and starts hunting your browser data, crypto wallets, password managers, even your macOS Keychain. Then comes the shove: a macOS password prompt pops up during this web “verification.” If you don’t enter it, apps keep force-closing until you give in, and the theft finishes quietly. Remember this: a website that tells you to paste a command into Terminal is almost always a scam. Close the tab immediately and report it to IT.

Similar attacks

ClickLock Tricks Mac Users Into Running Malware

ClickLock Tricks Mac Users Into Running Malware

A macOS info-stealing malware called ClickLock Stealer uses a fake “Cloudflare verification” page to trick users into copying and running a Terminal command. It then steals browser, crypto wallet, and Keychain data and sends it to attackers via a Telegram bot, while killing processes to hide…

July 16, 2026
ClickLock macOS Stealer Forces Password via Kill Loops

ClickLock macOS Stealer Forces Password via Kill Loops

Researchers observed a real macOS information-stealing campaign that tricks victims into pasting a command into Terminal from a “ClickFix” web page. After running, the malware shows a fake macOS password prompt and can repeatedly crash key apps (Finder/Dock/browsers) for hours or days to pressure…

July 16, 2026
ClickLock Stealer Freezes Macs for Passwords

ClickLock Stealer Freezes Macs for Passwords

Researchers found a new macOS infostealer, “ClickLock Stealer,” that uses ClickFix-style fake verification pages to trick people into running Terminal commands. After infection, it shows a realistic macOS password prompt and can effectively lock the Mac until the victim enters the correct password,…

July 21, 2026
Fake Install Guides and Helpdesk Calls Drive Attacks

Fake Install Guides and Helpdesk Calls Drive Attacks

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result “install guide,” a recruiter outreach, or a helpdesk phone call. The lures push victims to paste commands, install fake software, or reset MFA,…

July 30, 2026
LogoKit Builds Real-Time Fake Login Pages

LogoKit Builds Real-Time Fake Login Pages

Researchers observed LogoKit phishing campaigns that create a unique fake login page for each recipient in real time. The kit pulls a live screenshot of the victim organization’s real website and uses legitimate online services to make the phishing page look familiar, then steals credentials and…

July 29, 2026
“Work Panel” Streamlines Vishing Into One Console

“Work Panel” Streamlines Vishing Into One Console

Okta says it gained an inside look at “Work Panel,” a polished SaaS-style dashboard that helps voice-phishing (vishing) crews rapidly set up fake login sites and guide victims through password and MFA capture. The tool clones brand look-and-feel for services like Okta and Microsoft 365, then lets a…

July 29, 2026