Group-IB identified a new ClickLock macOS malware campaign targeting macOS users.
The attack likely begins with a ClickFix-style lure that tricks users into running a malicious Terminal command.
If the fake password prompt is dismissed, ClickLock establishes persistence through LaunchAgents and resumes after the next login, where it repeatedly terminates key macOS processes until the password is entered.
The malware steals credentials, browser data, wallet files, macOS authentication data, and can install a persistent backdoor.
Users should never run Terminal commands from untrusted websites and should boot into Safe Mode if ClickLock renders the system unresponsive.
Note: Safe Mode steps differ by Mac architecture. On Intel Macs, hold Shift during startup. On Apple silicon Macs, press and hold the Power button to open Startup Options, then hold Shift and select Continue in Safe Mode.
The newly identified ClickLock macOS malware demonstrates that attackers do not always need software vulnerabilities to compromise enterprise devices. Instead, the malware relies on social engineering, tricking users into running a malicious Terminal command before coercing them into entering their macOS login password through persistent fake password prompts.
According to Group-IB, ClickLock is a modular macOS infostealer that targets browser credentials, cryptocurrency wallets, password-manager data, macOS authentication information, and other sensitive files. If victims dismiss the initial fake password prompt, the malware establishes persistence through LaunchAgents and later repeatedly terminates key macOS processes until valid credentials are entered.
For organizations managing macOS fleets, the incident highlights how user-driven attacks can circumvent technical safeguards without exploiting the operating system itself. Endpoint visibility, application control, user awareness, and rapid investigation remain essential to protecting enterprise devices.
According to Group-IB, the attack likely begins with a fake Cloudflare verification page using a ClickFix macOS lure. Victims are tricked into running a malicious Terminal command that downloads additional malware while hiding the Terminal cursor and Notification Center alerts.
The malware then displays a fake macOS password prompt using the victim’s username and Apple branding. If the password is entered, ClickLock validates and sends it to the attacker.
If the prompt is dismissed, ClickLock persists through LaunchAgents and resumes after the next login. It then terminates key macOS applications every 210 milliseconds, leaving the fake password prompt as the only usable interface.
The process-killing loop targets applications including:
Finder and Dock
Terminal and Activity Monitor
System Settings and Spotlight
Web browsers and other visible applications
According to Group-IB, this coercion loop can continue for approximately 83 hours unless interrupted.
Investigation Priorities for ClickLock Activity
Investigation signal
Why it matters
Unexpected Terminal execution
May indicate execution of a malicious Terminal command.
New or unfamiliar LaunchAgents
Could indicate persistence established after the initial compromise.
Repeated termination of core macOS processes
Matches ClickLock’s reported coercion behavior.
Access to browser profiles or authentication stores
May indicate credential collection activity.
Outbound communication to Telegram infrastructure
May suggest data exfiltration through the Telegram Bot API.
Unexpected reverse-shell behavior
Could indicate deployment of the reported GSocket-based backdoor.
Why This Malware Is Different from Traditional macOS Infostealers
Many information stealers attempt to collect credentials quietly. ClickLock instead focuses on forcing user interaction.
Rather than exploiting a macOS vulnerability, it pressures users into entering their login password through repeated interruption of normal desktop operations. Public reporting indicates that the malware can also request legitimate Keychain authorization to access Chrome Safe Storage, allowing attackers to decrypt Chromium passwords, cookies, and autofill data after user approval.
Once active, ClickLock reportedly gathers:
Browser profiles, cookies, and saved credentials
Password-manager extension data
Cryptocurrency wallet files
Shell histories
FileZilla configuration data
System information and public IP address
macOS authentication-related information
The collected data is archived and uploaded through the Telegram Bot API. The malware also deploys a modified GSocket backdoor that provides persistent remote access to infected systems. At the time of reporting, the campaign had not been attributed to a known threat actor.
What is Threat Analysis?
Learn threat analysis for faster detection, investigation, prioritization, and response.
Why Enterprise macOS Fleets Should Pay Attention
A compromised employee Mac can expose more than local credentials. Developers, administrators, executives, contractors, and remote employees often access cloud services, VPNs, internal repositories, collaboration platforms, and enterprise applications from managed macOS devices.
If authentication material or browser sessions are compromised, attackers may gain opportunities to access additional enterprise resources, depending on an organization’s authentication and access controls.
Although public reporting has not confirmed broader enterprise compromise resulting from ClickLock, its credential theft, persistence, and remote access capabilities make rapid investigation important for organizations managing macOS endpoints.
Supporting Enterprise Response with Hexnode
This incident highlights the importance of combining endpoint management with endpoint detection and investigation to reduce the impact of credential-focused attacks.
Organizations can use Hexnode UEM to reduce exposure by:
Enforcing macOS updates across managed devices
Restricting unauthorized applications and scripts through policy controls
Monitoring device compliance before granting access to enterprise resources
Enforcing FileVault encryption and security configurations
Maintaining centralized visibility across managed macOS endpoints
Hexnode XDR can complement these controls by helping security teams investigate suspicious endpoint activity during incident response. It also supports incident investigations by helping security teams review endpoint activity and prioritize response alongside their existing security workflows.
Together, Hexnode UEM and Hexnode XDR help organizations manage device security, maintain endpoint visibility, and support incident response for threats such as ClickLock macOS malware, alongside vendor guidance, log analysis, and forensic investigation.
Featured Resource
Hexnode XDR Info Sheet
Strengthen endpoint security with unified detection, investigation, visibility, and UEM-driven response through Hexnode XDR integration.
The ClickLock macOS malware campaign shows how attackers can steal legitimate credentials through social engineering instead of exploiting operating system vulnerabilities. By combining deceptive Terminal commands with persistent password coercion, the malware relies on user interaction to compromise systems.
For enterprise security teams, reducing risk requires user awareness, application controls, endpoint management, rapid investigation of suspicious persistence, and layered macOS endpoint security. Together, these measures can help limit the impact of credential-focused attacks.
Strengthen every managed macOS endpoint
Start your free trial to improve endpoint visibility and policy enforcement.
Yes. According to Group-IB, if the initial password prompt is dismissed, ClickLock can establish persistence through LaunchAgents, allowing it to resume after the next login.
Who is at greatest risk from ClickLock?
Organizations with managed macOS devices, especially those used by developers, administrators, executives, and other employees with access to sensitive enterprise resources, should be particularly vigilant.
Has ClickLock been linked to a known threat actor?
No. At the time of reporting, public research had not attributed the ClickLock campaign to a specific threat actor.
A storyteller for practical people. Breaks down complicated topics into steps, trade-offs, and clear next actions—without the buzzword fog. Known to replace fluff with facts, sharpen the message, and keep things readable—politely.