Illustrative photo of a Mac desktop trapped behind a fake password prompt and terminated windows

ClickLock makes Macs unusable to steal passwords

Group-IB says the new macOS stealer uses coercion, not an exploit.

July 20, 2026OneMoreThing Editorial4 minProducts

Group-IB identified ClickLock Stealer in a campaign active since May 2026. It has targeted at least 100 systems in 33 countries, with more than half of the identified targets in Europe. The initial command likely arrives through ClickFix-style pages, but Group-IB did not directly observe the landing pages.

After the command runs, ClickLock repeatedly terminates interactive apps about every 210 milliseconds. A fake password dialog remains on screen and pressures the user to enter credentials. One loop can run for about 83 hours; other components seek browser data, Keychain material, password managers, and crypto wallets, then send archives to Telegram.

This is not a conventional screen lock or a confirmed macOS exploit. It is social engineering that turns the desktop into a coercive prompt. Users should never paste a Terminal command suggested by a webpage. If the behavior appears, disconnect the Mac, shut it down, change passwords from a clean device, and seek professional remediation; Safe Mode alone is not proof of removal.

Sources
Group-IB — ClickLock Stealer
BleepingComputer — New ClickLock macOS malware traps users into revealing login password
FRJAZHRUES