ClickLock malware makes Macs unusable until victims surrender their passwords
AI-summarised brief · reviewed before publication
Security firm Group‑IB has identified ClickLock Stealer, a new Mac malware that forces users to surrender passwords by hijacking system prompts. Since May 2026, the campaign has targeted at least 100 victims across 33 countries, with over half of the activity in Europe and additional incidents in North America, the Middle East, and Africa. ClickLock builds on the familiar ClickFix scam, adding a coercive step that appears after a user cancels a password prompt. The malicious script downloads components to steal credentials, browser data, cryptocurrency information, and installs a persistent backdoor in the macOS Keychain.
💡 Why It Matters
- · The attack exploits a psychological pressure point, turning routine password prompts into coercive demands, revealing a new vector for credential theft that could undermine user trust in macOS security.