
ClickLock makes Macs unusable to steal passwords
Group-IB says the new macOS stealer uses coercion, not an exploit.
Group-IB identified ClickLock Stealer in a campaign active since May 2026. It has targeted at least 100 systems in 33 countries, with more than half of the identified targets in Europe. The initial command likely arrives through ClickFix-style pages, but Group-IB did not directly observe the landing pages.
After the command runs, ClickLock repeatedly terminates interactive apps about every 210 milliseconds. A fake password dialog remains on screen and pressures the user to enter credentials. One loop can run for about 83 hours; other components seek browser data, Keychain material, password managers, and crypto wallets, then send archives to Telegram.
This is not a conventional screen lock or a confirmed macOS exploit. It is social engineering that turns the desktop into a coercive prompt. Users should never paste a Terminal command suggested by a webpage. If the behavior appears, disconnect the Mac, shut it down, change passwords from a clean device, and seek professional remediation; Safe Mode alone is not proof of removal.