{*}
Add news
March 2010 April 2010 May 2010 June 2010 July 2010
August 2010
September 2010 October 2010 November 2010 December 2010 January 2011 February 2011 March 2011 April 2011 May 2011 June 2011 July 2011 August 2011 September 2011 October 2011 November 2011 December 2011 January 2012 February 2012 March 2012 April 2012 May 2012 June 2012 July 2012 August 2012 September 2012 October 2012 November 2012 December 2012 January 2013 February 2013 March 2013 April 2013 May 2013 June 2013 July 2013 August 2013 September 2013 October 2013 November 2013 December 2013 January 2014 February 2014 March 2014 April 2014 May 2014 June 2014 July 2014 August 2014 September 2014 October 2014 November 2014 December 2014 January 2015 February 2015 March 2015 April 2015 May 2015 June 2015 July 2015 August 2015 September 2015 October 2015 November 2015 December 2015 January 2016 February 2016 March 2016 April 2016 May 2016 June 2016 July 2016 August 2016 September 2016 October 2016 November 2016 December 2016 January 2017 February 2017 March 2017 April 2017 May 2017 June 2017 July 2017 August 2017 September 2017 October 2017 November 2017 December 2017 January 2018 February 2018 March 2018 April 2018 May 2018 June 2018 July 2018 August 2018 September 2018 October 2018 November 2018 December 2018 January 2019 February 2019 March 2019 April 2019 May 2019 June 2019 July 2019 August 2019 September 2019 October 2019 November 2019 December 2019 January 2020 February 2020 March 2020 April 2020 May 2020 June 2020 July 2020 August 2020 September 2020 October 2020 November 2020 December 2020 January 2021 February 2021 March 2021 April 2021 May 2021 June 2021 July 2021 August 2021 September 2021 October 2021 November 2021 December 2021 January 2022 February 2022 March 2022 April 2022 May 2022 June 2022 July 2022 August 2022 September 2022 October 2022 November 2022 December 2022 January 2023 February 2023 March 2023 April 2023 May 2023 June 2023 July 2023 August 2023 September 2023 October 2023 November 2023 December 2023 January 2024 February 2024 March 2024 April 2024 May 2024 June 2024 July 2024 August 2024 September 2024 October 2024 November 2024 December 2024 January 2025 February 2025 March 2025 April 2025 May 2025 June 2025 July 2025 August 2025 September 2025 October 2025 November 2025 December 2025 January 2026 February 2026 March 2026 April 2026 May 2026 June 2026 July 2026
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26
27
28
29
30
31
News Every Day |

ClickLock Mac malware locks apps until you give in

A routine "verify you are human" page should never ask you to open Terminal, the Mac app used to run computer commands. Yet that is how a new malware attack appears to get onto a Mac. The page tells you to copy and paste a command into Terminal. It then shows a convincing progress bar while the command quietly downloads malicious software in the background.

Next, a password box may appear that looks like a normal macOS request. If you cancel it, the malware can come back after you sign in again and repeatedly close Finder, your browser and other apps. Your Mac may feel almost impossible to use until you enter your login password.

The malware, called ClickLock, is built to steal personal information from your Mac. It searches for saved passwords, browser data and cryptocurrency wallet files. It can also install a hidden tool that lets an attacker reconnect to your computer later and control it remotely.

Researchers at cybersecurity company Group-IB discovered the malicious script on VirusTotal, an online service that checks files for threats. Someone first uploaded it there on June 9, 2026, yet none of the security tools on the platform detected it at the time of the researchers' report. Group-IB says the campaign has targeted at least 100 systems across 33 countries since May.

Here is how ClickLock takes over a Mac and what you can do to protect yourself.

CyberGuy Live: Missed "Sick of Spam?" Get the replay and checklist

Our free CyberGuy Live class, "Sick of Spam?" , has ended, but you can still watch the full replay and download our spam-stopping checklist. Kurt "CyberGuy" Knutsson walks you step by step through simple ways to reduce robocalls, spam texts, junk email and unwanted messages. You’ll also learn how to curb political texts, clean up your inbox and spot messages that could put your personal information at risk.

Get the free replay and checklist now at CyberGuyLive.com.

FAKE PASSWORD-MANAGER ALERTS COULD PUT YOUR VAULT AT RISK

ClickLock is a set of malicious scripts designed to steal sensitive information from a Mac. The malware can collect your Mac login password and browser data. It also searches for cryptocurrency wallet files, password manager extensions and information stored in macOS Keychain.

One component installs a persistent backdoor. That hidden connection can allow an attacker to access your Mac remotely even after the other parts of ClickLock remove themselves.

ClickLock gets started without exploiting a known macOS flaw. It also does not need admin-level access at the beginning. Instead, the attack depends on convincing you to run the command yourself.

Group-IB believes ClickLock likely spreads through a tactic called ClickFix. ClickFix attacks show you a fake error or verification request. The page then gives you a command that supposedly fixes the problem.

In this case, the ClickLock script displays a fake Cloudflare verification sequence after you paste the command into Terminal. An animated progress bar cycles through reassuring messages about checking browser signals and confirming you are human.

Meanwhile, the script disables keyboard interruptions and hides the Terminal cursor. It then downloads several malicious components in the background. Researchers have yet to confirm the exact landing pages used in the campaign. They also do not know whether people reached them through malicious search results, compromised websites, phishing messages or social media. However, the script's design strongly points to a ClickFix-style lure.

After the malware begins running, it displays a fake macOS password window. The pop-up uses your real username and an Apple icon downloaded by the attacker. If you enter a password, ClickLock checks it against your Mac. When the password works, the malware records it and sends it to the attacker through Telegram.

An incorrect password brings up another request. If you cancel the window, ClickLock installs two LaunchAgents. A LaunchAgent is a macOS instruction that can automatically run software when you sign in. In this case, the LaunchAgents bring the password-stealing components back at your next login.

HALLUSQUATTING AI ATTACK COULD HIJACK YOUR COMPUTER

When the password-stealing module returns, it begins closing visible apps every 210 milliseconds. It targets Finder, the Dock and Terminal. It also shuts down Activity Monitor, System Settings, Spotlight and common web browsers.

The fake password window may remain as the only useful item on your screen. That can make your Mac look broken while pressuring you to enter your password. Group-IB found that the loop can run for about 83 hours. It stops earlier when the malware captures a valid password.

A second ClickLock component targets Chrome's Safe Storage key. Chromium-based browsers use this key to help encrypt passwords, cookies and autofill information stored on your Mac. An attacker with the key and copied browser databases may be able to decrypt that information offline.

This part of the attack triggers a genuine macOS Keychain authorization prompt. However, the malware caused the request. ClickLock then runs another process-closing loop while waiting for you to approve access. Researchers found that this loop repeats every 200 milliseconds and can continue for nearly 35 days. The script also suppresses macOS NotificationCenter for roughly six hours. That could hide warnings or notifications that might reveal the attack.

ClickLock searches for information across eight browsers. Those browsers include Chrome, Firefox, Brave, Microsoft Edge, Opera, Vivaldi, Arc and Chromium.

The targeted browser information includes:

The malware also searches for desktop cryptocurrency wallets and encrypted wallet vaults. It can collect cached blockchain addresses across several networks. Other targets include macOS Keychain, Terminal command histories and FileZilla server details. The malware also records basic information about your Mac and its public IP address. ClickLock packages the collected information into a ZIP archive. It uploads that archive through Telegram's Bot API. Files larger than 40 MB get divided into smaller pieces, while retry code keeps trying after network failures.

One ClickLock component uses a modified version of the open-source GSocket tool. The malware installs a reverse shell, which gives the attacker a command-line connection to your Mac. On macOS, it disguises the backdoor as an iCloud-related process.

ClickLock uses a LaunchAgent and scheduled commands to keep the backdoor running. It also changes shell configuration files. Most of the other ClickLock modules delete themselves after completing their work. The GSocket component remains installed, which means the attacker may retain access after your Mac appears to return to normal.

The original ClickLock script had zero detections on VirusTotal when Group-IB analyzed it. Security vendors may update their detection tools as they learn more about the threat. The attackers also stored payloads on compromised websites that previously had clean reputations. Some components run without saving a normal file to the drive. Others erase themselves after stealing data.

However, ClickLock still produces suspicious activity while it runs. Warning signs include nonstop app closures, repeated password requests and sudden access to multiple browser folders. Security tools may also detect unusual connections to Telegram's API. For you, the earliest warning sign is much simpler. A website tells you to paste a command into Terminal. Legitimate human verification happens inside your browser. It should never require you to run a Terminal command.

These steps can help you avoid the ClickLock trap and respond quickly if the password loop starts.

Leave the page when it tells you to open Terminal and paste a command. A polished design offers no proof that the request is safe. Familiar logos can also be copied. Group-IB warns that a website asking you to use Terminal for verification is attempting to compromise your system.

Terminal commands can download software and change important settings. Never run an unfamiliar command simply to see what happens. Ask a trusted technical professional to inspect it first.

Think about what you were doing when the password window appeared. A website verification should have no reason to ask for your Mac login password. It should also have no reason to request access to Chrome information stored in Keychain. Cancel the request when the timing feels wrong.

Install macOS updates and keep automatic security updates turned on. Apple builds malware protection into macOS through Gatekeeper, Notarization and XProtect. Apple updates XProtect automatically as it identifies new malware. However, no built-in protection can eliminate every risk when you manually run a malicious command.

Strong antivirus software can provide another layer of protection against malicious files and suspicious behavior. Still, a clean scan cannot guarantee that ClickLock left nothing behind. The backdoor persists after other components erase themselves. Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android & iOS devices at Cyberguy.com

Do not enter your password to make the pop-up disappear. Press and hold your Mac's power button for up to 10 seconds until the computer shuts down. On a MacBook with Touch ID, press and hold the Touch ID button. Group-IB recommends forcing a shutdown when your Mac becomes unresponsive and keeps requesting your password. The company then recommends starting the Mac in Safe Mode.

Mac with Apple silicon: Wait until the Mac shuts down completely. Press and hold the power button until "Loading startup options" appears. Select your startup volume. Hold the Shift key, then click Continue in Safe Mode.

Intel-based Mac: Turn on or restart the Mac. Immediately press and hold the Shift key until the login window appears.

Once Safe Mode starts, turn off Wi-Fi or unplug the Ethernet cable. Then contact Apple Support or a trusted cybersecurity professional. Removing a browser extension or clearing your history will not remove ClickLock's persistent backdoor.

Use a separate trusted device to change the password for your primary email account. Then secure your Apple Account and any financial accounts stored on the Mac. Change password manager credentials and review active sessions. Sign out of devices or sessions you do not recognize. Review the devices connected to your Apple Account and remove unfamiliar ones. Apple also recommends changing your Apple Account password when you suspect unauthorized access. After a professional cleans or resets the Mac, change its local login password. Assume the attacker received that password if you entered it into the ClickLock window.

ClickLock depends on one dangerous moment: convincing you to paste a command into Terminal. Once that happens, the malware can begin stealing information before the password pressure even starts. The biggest red flag is easy to remember. No trustworthy website needs Terminal to prove you are human. If your Mac starts closing apps and demanding a password, shut it down rather than giving in. Start in Safe Mode and get help checking for the persistent backdoor. Then use another trusted device to secure your most important accounts.

Have you ever seen a suspicious password prompt or fake verification page on your Mac? Tell us what it looked like and what you did next in the comments below. Let us know by writing to us at Cyberguy.com

Sign up for my FREE CyberGuy Report

Copyright 2026 CyberGuy.com. All rights reserved.

Ria.city






Read also

NEET-UG row: Assam minister Mahanta’s daughter joins protest, CM Himanta says ‘she may not follow her father’s ideology’

'Attacked multiple times with sickle': Man arrested for killing 8-month-pregnant wife in UP

Hatchet jobs, fights, and one very divisive song: Razorlight’s Johnny Borrell on making indie’s most notorious second album

News, articles, comments, with a minute-by-minute update, now on Today24.pro

Today24.pro — latest news 24/7. You can add your news instantly now — here




Sports today


Новости тенниса


Спорт в России и мире


All sports news today





Sports in Russia today


Новости России


Russian.city



Губернаторы России









Путин в России и мире







Персональные новости
Russian.city





Friends of Today24

Музыкальные новости

Персональные новости