A Mac malware campaign active since May 2026 has stolen credentials from victims across 33 countries by locking users out of their own computers until they hand over their passwords, according to security firm Group-IB.
The malware, called ClickLock Stealer, works without exploiting any software vulnerability.
No hacking in the traditional sense is required. Victims are tricked into opening Terminal and pasting in a command themselves, after which the attack runs automatically.
What Users Actually See on Screen
The entry point appears to be a fake webpage that mimics a Cloudflare security check or browser verification screen.
The page instructs visitors to copy a command and paste it into Terminal as part of the supposed verification process.
Once run, the script downloads additional components in the background while displaying what appears to be a Cloudflare progress bar.
After that, a password prompt appears. If the user dismisses it, the malware begins closing every open application every 210 milliseconds, making the Mac effectively unusable.
The desktop stays locked in that state until the user gives up and enters their login password. A separate process running in the background suppresses macOS security alerts for approximately six hours.
What Gets Stolen After That
Entering the password does not end the attack. A second prompt then appears, this time a genuine macOS dialog asking for access to a Keychain item.
If the user approves it, the malware obtains Chrome’s Safe Storage key, which is the encryption key Chrome uses to protect every saved password and browser cookie on the machine.
With both the login password and Chrome’s encryption key obtained, ClickLock pulls saved browser passwords, Keychain entries, any password manager vaults stored on the device, and cryptocurrency wallet data. Everything gets sent to a Telegram bot.
The malware also installs a hidden backdoor disguised as an iCloud process, giving the attacker ongoing access to the machine even after the initial theft.
Group-IB says more than half of the 100-plus confirmed victims are based in Europe.
Apple Has Already Added a Defense in macOS Tahoe 26.4
Apple added a protection in macOS Tahoe 26.4 that triggers whenever a user tries to paste a command into Terminal that originated on a website, in a chat app, or in a message.
A warning appears and blocks the paste until the user actively reviews what they are about to run.
If macOS identifies the content as known malware, the paste is blocked entirely with no way to override it. Opera added a similar clipboard protection feature to its browser earlier this month.
Users running older versions of macOS do not have that protection. The most reliable defense remains the same regardless of operating system version: no legitimate website, verification page, or security check will ever ask someone to open Terminal and paste a command into it.