'ClickLock' Malware Coerces Mac Users Into Giving Up Passwords
'ClickLock' Malware Coerces Mac Users Into Giving Up PasswordsMonday July 20, 2026 6:17 am PDT by Tim HardwickSecurity firm Group-IB has identified a new piece of macOS malware in the wild that pressures users into surrendering their passwords via a barrage of fake system prompts. Dubbed "ClickLock Stealer," the malware needs no exploits and no elevated privileges to work. Instead, the attack depends on the victim pasting a command into Terminal and running it.
- ▪'ClickLock' Malware Coerces Mac Users Into Giving Up PasswordsMonday July 20, 2026 6:17 am PDT by Tim HardwickSecurity firm Group-IB has identified a new piece of macOS malware in the wild that pressures users into surrendering their passwo
- ▪Dubbed "ClickLock Stealer," the malware needs no exploits and no elevated privileges to work.
- ▪Instead, the attack depends on the victim pasting a command into Terminal and running it.
Opening excerpt (first ~120 words) tap to expand
'ClickLock' Malware Coerces Mac Users Into Giving Up PasswordsMonday July 20, 2026 6:17 am PDT by Tim HardwickSecurity firm Group-IB has identified a new piece of macOS malware in the wild that pressures users into surrendering their passwords via a barrage of fake system prompts. Dubbed "ClickLock Stealer," the malware needs no exploits and no elevated privileges to work. Instead, the attack depends on the victim pasting a command into Terminal and running it. The command then executes a script, and everything else follows. Group-IB did not directly observe how victims are lured into pasting the command, but based on the script's behavior, the firm believes it's served through a fake "ClickFix" page posing as a Cloudflare check or browser verification step.
…
Excerpt limited to ~120 words for fair-use compliance. The full article is at MacRumors.