iOS 26

iPhone

iPad

Apple Watch

AirPods

Apple Deals

Apple Already Fixed This Dangerous Mac Scam for Some Users, but Millions Could Still Be Wide Open to the Same Attack

Gotechtor select and review products independently. When you purchase through our links, we may earn a commission. See our ethics statement.

A Mac malware campaign active since May 2026 has stolen credentials from victims across 33 countries by locking users out of their own computers until they hand over their passwords, according to security firm Group-IB.

The malware, called ClickLock Stealer, works without exploiting any software vulnerability.

No hacking in the traditional sense is required. Victims are tricked into opening Terminal and pasting in a command themselves, after which the attack runs automatically.

What Users Actually See on Screen

The entry point appears to be a fake webpage that mimics a Cloudflare security check or browser verification screen.

The page instructs visitors to copy a command and paste it into Terminal as part of the supposed verification process.

Once run, the script downloads additional components in the background while displaying what appears to be a Cloudflare progress bar.

After that, a password prompt appears. If the user dismisses it, the malware begins closing every open application every 210 milliseconds, making the Mac effectively unusable.

The desktop stays locked in that state until the user gives up and enters their login password. A separate process running in the background suppresses macOS security alerts for approximately six hours.

Also: Everyone expected Apple to go after Jony Ive in the OpenAI lawsuit, but he was quietly left out for a reason

What Gets Stolen After That

Entering the password does not end the attack. A second prompt then appears, this time a genuine macOS dialog asking for access to a Keychain item.

If the user approves it, the malware obtains Chrome’s Safe Storage key, which is the encryption key Chrome uses to protect every saved password and browser cookie on the machine.

With both the login password and Chrome’s encryption key obtained, ClickLock pulls saved browser passwords, Keychain entries, any password manager vaults stored on the device, and cryptocurrency wallet data. Everything gets sent to a Telegram bot.

The malware also installs a hidden backdoor disguised as an iCloud process, giving the attacker ongoing access to the machine even after the initial theft.

Group-IB says more than half of the 100-plus confirmed victims are based in Europe.

Also: If you’ve never tried Apple’s sports app, this new soccer upgrade might finally give you a good reason

Apple Has Already Added a Defense in macOS Tahoe 26.4

Apple added a protection in macOS Tahoe 26.4 that triggers whenever a user tries to paste a command into Terminal that originated on a website, in a chat app, or in a message.

A warning appears and blocks the paste until the user actively reviews what they are about to run.

If macOS identifies the content as known malware, the paste is blocked entirely with no way to override it. Opera added a similar clipboard protection feature to its browser earlier this month.

Users running older versions of macOS do not have that protection. The most reliable defense remains the same regardless of operating system version: no legitimate website, verification page, or security check will ever ask someone to open Terminal and paste a command into it.

🍎 The only 5 Apple stories that matter — sent every Friday to 50K+ smart readers. You in?

Founder & Editor-in-Chief

Herby has a healthy obsession with all things Apple, especially the iPhone. He loves to rip things apart to see how they work. He is responsible for the editorial direction, strategy, and growth of Gotechtor.

Herby Jasmin

's latest stories

Leave a Comment

Be kind. Discriminatory language, personal attacks, promotion, and spam will be removed. Please read Gotechtor's Community Guidelines before participating.