ClickLock Stealer malware locks macOS devices worldwide
Group‑IB has identified a new macOS‑targeted malware called ClickLock Stealer. The strain spreads through fake web pages that ask users to copy a command into the macOS Terminal. Once executed, the code downloads additional modules, disables security notifications and repeatedly forces open applications to close, rendering the computer unusable until the victim enters an administrator password.
After the password is supplied, the malware harvests the user’s iCloud Keychain, browser credentials and cryptocurrency wallet keys, sending the data to a Telegram bot. The campaign, active since May 2026, has already reached users in more than 30 countries. Apple responded by adding a warning in macOS Tahoe 26.4 that blocks the execution of pasted commands from external sources, reminding users that legitimate sites never require Terminal use.
The threat relies solely on social‑engineering rather than exploiting system vulnerabilities, making it effective against any macOS device whose user follows the deceptive instructions.