A genuine verification page should never prompt you to open the Terminal, a Mac application used for running commands. However, a new malware attack utilizes this method to infiltrate Macs. The page instructs users to copy and paste a command into Terminal, accompanied by a progress bar that stealthily downloads harmful software.
Malware Can Make Your Mac Unusable
A password window, resembling a standard macOS request, may appear. Canceling it might not resolve the issue. The malware, known as ClickLock, can return and close Finder, your browser, and other applications repeatedly, making your Mac difficult to operate until you input your login password.
What ClickLock Targets
ClickLock aims to steal personal details from your Mac. It seeks saved passwords, browser data, and cryptocurrency wallet files. Moreover, it incorporates a hidden tool facilitating remote access to your computer by an attacker post-initial infiltration.
Cybersecurity Discovery
Cybersecurity firm Group-IB uncovered the malicious script on VirusTotal, a service that checks files for threats. The script was first uploaded on June 9, 2026, yet security tools failed to detect the threat. Since May, Group-IB reports the campaign has targeted at least 100 systems in 33 countries.
How ClickLock Begins
ClickLock uses a fake verification page to lure users into pasting commands in Terminal. This page displays a bogus Cloudflare verification after the command is entered. An animated progress bar depicts reassuring messages about checking browser signals and confirming user authenticity.
The script disables keyboard interruptions, conceals the Terminal cursor, and downloads malicious elements in the background.
Researchers have not yet verified the exact landing pages used but believe the design aligns with ClickFix-style tactics.
Password Traps and App Closures
ClickLock’s attack proceeds with a fake macOS password prompt, using your real username and an Apple icon. Inputting a password allows the malware to record and send it to the attacker via Telegram.
If the password is incorrect, it triggers further requests. Canceling the prompt results in ClickLock installing two LaunchAgents, which resurrect the malware components upon next login.
When the malware returns, it closes visible applications approximately every 210 milliseconds, affecting Finder, the Dock, and Terminal. Only the fraudulent password window remains active, urging you to input your password.
Changing Browser Security
A second component of ClickLock targets the Chrome Safe Storage key. This key encrypts browser-stored passwords, cookies, and autofill information. Obtaining this key, alongside browser databases, allows for offline decryption.
This segment induces a genuine macOS Keychain authorization prompt—though malware causes it—and runs a process-closing cycle while awaiting your response.
What ClickLock Seeks
ClickLock targets data across eight browsers: Chrome, Firefox, Brave, Microsoft Edge, Opera, Vivaldi, Arc, and Chromium. Data targeted includes saved usernames, passwords, cookies, session data, bookmarks, and cryptocurrency wallet extensions.
ClickLock’s Persistent Backdoor
This malware installs a reverse shell, granting command-line access to your Mac. It disguises itself as an iCloud-related process.
The attacker may retain access even after the Mac seemingly returns to normal, given the enduring nature of the backdoor component.
Detection Challenges
ClickLock initially had zero detections on VirusTotal. Its components run without leaving traces on the drive and erase themselves post-data theft.
Suspicious activities remain, including nonstop app closures, repeated password requests, and unexpected access to browser folders.
If a website prompts you to paste a Terminal command, it generally signals an attempted compromise.
Protection Strategies
- Close any site directing you to Terminal and leave the page immediately.
- Understand commands before execution. Unknown commands can download harmful software.
- Question unexpected password requests. Consider what you were doing before the prompt appeared.
- Keep macOS and antivirus software current for additional security layers.
- Upon suspicious activity, shut down your Mac immediately and restart in Safe Mode.
- Use another trusted device to secure accounts potentially affected by ClickLock.
Have you encountered suspicious activity or verification prompts on your Mac? Share your experience in the comments section below or contact us at Cyberguy.com.
For more security tips and alerts, sign up for the CyberGuy Report and access free scam survival guides at CyberGuy.com.
Kurt “CyberGuy” Knutsson is an established tech journalist contributing regularly to Fox News and FOX Business. For questions, sign up for the CyberGuy Newsletter or visit CyberGuy.com.
