💛 A quick favor, if you've got a second.
We're really happy that you chose to read one of our stories and sincerely hope you'll stick around to read more. We took our paywall down — for now — but that won't last forever, and when the gate goes back up, we'd love for you to already be on the inside.
It's free. So please enter your email here and don't forget to like and follow us on all of your favorite Social Media platforms!

A new malware variant called ClickLock has emerged as a significant threat to Mac users, employing social engineering tactics that trick victims into running malicious commands through Terminal. The attack begins with a deceptive verification page that mimics legitimate Cloudflare prompts, instructing users to copy and paste code into their computer’s command-line interface. Security researchers at Group-IB discovered the malicious script uploaded to VirusTotal on June 9, 2026, with zero initial detections across security platforms at the time of analysis.
The ClickLock campaign has compromised at least 100 systems across 33 countries since May, according to Group-IB’s findings. Once executed, the malware displays a fake macOS password prompt resembling authentic system requests, complete with the user’s actual username and Apple branding. If victims enter their login credentials, ClickLock captures and transmits the password to attackers via Telegram’s API, while incorrect entries trigger repeated password requests designed to pressure compliance.
When users cancel the password window, the malware installs LaunchAgents that automatically reactivate the attack upon next login. The malware then enters a destructive loop, forcibly closing Finder, browsers, System Settings and other applications every 210 milliseconds, rendering the Mac nearly unusable and intensifying pressure on victims to provide their passwords. This cycle can persist for approximately 83 hours until a valid credential is captured.
Beyond password theft, ClickLock targets sensitive data including Chrome’s Safe Storage encryption key, browser cookies and autofill information across eight browsers: Chrome, Firefox, Brave, Microsoft Edge, Opera, Vivaldi, Arc and Chromium. The malware searches for cryptocurrency wallet files, password manager extensions, macOS Keychain data and Terminal command histories before packaging stolen information into encrypted archives for exfiltration.
A particularly dangerous component installs a persistent backdoor using a modified GSocket tool, disguised as an iCloud process through LaunchAgent configuration. This reverse shell grants attackers command-line access to the compromised Mac even after other ClickLock modules self-delete, potentially allowing continued unauthorized access long after the initial infection appears resolved.
Group-IB attributes the campaign to a tactic called ClickFix, which displays fake error messages or verification requests on malicious or compromised websites. Researchers believe victims reach these pages through malicious search results, compromised legitimate websites, phishing messages or social media links, though exact landing pages remain unconfirmed.
Security experts recommend immediately closing any website requesting Terminal commands for human verification, as legitimate services authenticate users within browsers without requiring command-line access. Mac users experiencing sudden app closures, repeated password prompts or unexpected Keychain access requests should force a shutdown by holding the power button for 10 seconds rather than entering credentials.
Victims should restart their Mac in Safe Mode, disconnect from the internet and contact Apple Support or a trusted cybersecurity professional before attempting recovery. After professional remediation, users must change their Mac login password and secure critical accounts including email, Apple ID and financial services from a separate trusted device, assuming attackers obtained any passwords entered into ClickLock’s fake prompts.
More Stories
Toronto Police Probe Gunfire and Property Damage at Jewish Bakery Locations
Berlin Police Identify Suspect in Vehicle Attack at Pride Event
Three Arrested, 10 Vehicles Seized Following Large-Scale Street Takeover on Long Island