MacBook displaying a suspicious verification screen while applications appear to close in the background

ClickLock Stealer Targets Mac Users by Using Their Password Against Them

A newly discovered macOS threat called ClickLock Stealer is using social engineering, fake verification pages, and persistent system disruption to steal passwords and sensitive data from Mac users. Here’s how it works and how to stay protected.

ClickLock Stealer is a new malware threat designed specifically for macOS. Unlike many traditional malware campaigns that rely on software vulnerabilities, ClickLock focuses on convincing users to compromise their own devices.

Once installed, the malware attempts to steal passwords, browser data, cryptocurrency wallet information, and other sensitive information while making the infected Mac increasingly difficult to use.

What Is ClickLock Stealer?

ClickLock Stealer is a modular information-stealing malware family that targets macOS devices.

Once executed, it downloads additional components designed to collect a wide range of personal and financial information from an infected Mac.

The malware can target:

  • Browser passwords
  • Saved login sessions and cookies
  • Apple Keychain data
  • Password manager records
  • Cryptocurrency wallets
  • FTP credentials
  • Shell history

Its primary goal appears to be gathering valuable credentials and authentication data that can be used for financial gain or further account compromise.

How the Attack Starts

The attack relies heavily on social engineering.

Victims are typically presented with a website designed to look like a legitimate security verification page. These pages may imitate CAPTCHA systems or browser verification prompts and instruct visitors to copy and paste a command into Terminal.

After the command is executed, the malware begins downloading and launching its various components while displaying what appears to be a normal verification process.

At this stage, the infection has already begun.

Why ClickLock Is Different

Most malware attempts to remain hidden while collecting information in the background.

ClickLock takes a more aggressive approach.

After installation, it presents what appears to be a legitimate macOS password prompt. If the user enters their password, that information can be captured along with other sensitive data collected from the system.

If the user refuses to provide the password, ClickLock can begin repeatedly closing important applications and system processes.

These may include:

  • Finder
  • Terminal
  • Activity Monitor
  • System Settings
  • Spotlight
  • Popular web browsers

This behaviour can leave the Mac difficult to use and create pressure for the victim to comply with the request.

A Persistent Backdoor Creates Additional Risk

Beyond password theft, ClickLock also installs a persistent backdoor designed to maintain access to the infected Mac.

The malware can leave behind remote access components that continue operating even after other parts of the malware remove themselves.

This means a system may appear normal while unauthorised access remains active in the background.

What Information Is Being Targeted?

ClickLock is designed to collect information from multiple locations across macOS.

This includes:

  • Browser credentials
  • Saved autofill information
  • Cookies and authentication tokens
  • Password manager vaults
  • Apple Keychain entries
  • Cryptocurrency wallet data

By collecting both passwords and active session information, attackers may be able to access online accounts even if multi-factor authentication is enabled.

How to Protect Yourself

The most effective protection is understanding how legitimate services operate.

A genuine website should never require you to open Terminal and run commands as part of a verification process.

If you encounter a page requesting this action:

  • Close the page immediately.
  • Do not copy or run any commands.
  • Verify the legitimacy of the website through official channels.
  • Keep macOS updated with the latest security updates.
  • Be cautious of unexpected password prompts.

A healthy level of scepticism can prevent most attacks of this type.

What to Do If You Think You’re Infected

If you have already run a suspicious Terminal command:

  1. Disconnect the Mac from the internet.
  2. Avoid entering passwords into unexpected prompts.
  3. Restart the Mac in Safe Mode.
  4. Change critical passwords from a separate trusted device.
  5. Review recent account activity and active login sessions.
  6. Seek Your Mac Tech assistance if you are unsure whether the malware remains present.

Taking action quickly can reduce the risk of further compromise.

ClickLock Stealer highlights a growing trend in cybersecurity. Rather than attacking macOS directly, attackers are increasingly targeting user behaviour and trust.

The simplest defence remains the most effective: never run Terminal commands provided by unknown websites or unexpected prompts.

If you’re concerned about your Mac’s security or would like help checking for signs of compromise, Your Mac Tech can assist with a professional security assessment and cleanup.

ClickLock Stealer Targets Mac Users by Using Their Password Against Them