Unfortunately, new forms of malware appear regularly these days thanks to AI tools, including on macOS. Right now there is a specific type of malware that is very active: ClickFix, in the form of ClickLock malware.
This ClickLock malware blocks your Mac with a fake login screen that requires you to enter your password. Once you do that, the malware looks for passwords, data in your Keychain, crypto wallets and installs an app that allows remote access to your Mac.
How the ClickLock malware can trick you
Although macOS has powerful security features such as Gatekeeper and notarization, Mac users are not fully protected against malware. Today’s attacks often use social engineering instead of software exploits, allowing users to bypass Apple’s security measures themselves. ClickLock is an excellent example of this.
Threat intelligence company Group-IB first discovered the malware on VirusTotal, where it was not yet detected. They called it ClickLock, referring to the ClickFix scam and the locking technique used to enforce your password.
ClickLock uses a deceptive method similar to ClickFix, which has been worrying Mac users for months. It works by displaying a spoofed web page in the style of a Cloudflare “I am not a robot” window, prompting users to copy and paste a command into Terminal.

pasting the command into Terminal is all that is required. The command then starts a script that does not require an exploit or administrator password to run. Once activated, the script will show a Cloudflare-style loading bar to distract you.
Four components are downloaded and installed behind the scenes. The first three look for your passwords, the macOS Keychain and crypto wallets. The latter is a backdoor app that makes it possible to access the Mac remotely.
The script then displays a password window that looks exactly like the real macOS dialog box with your username and Apple logo. Enter your password, and the malware validates it and continues. If you cancel it, ClickLock will appear again the next time you log in.
In the next login attempt, the malware uses more aggressive methods. Nearly all open apps on your Mac will close, leaving only the fake login window visible. Whether it’s Finder, Terminal, or your browser, everything closes as soon as you open it. This only ends once you enter your password.
At the same time, another process of the malware suppresses macOS notifications for about six hours. That means you won’t get any security warnings.
![]() |
Category: Anti Virus Valuation: Developer: Intego From €2 per month |
After your password has been entered
Entering your Mac password doesn’t stop the attack, but helps it continue. The malware then shows a second macOS prompt asking you to grant access to the Chrome Keychain. By allowing this, you release the key that Chrome uses to protect saved passwords and cookies. This allows attackers to decrypt your data offline at their convenience.
ClickLock then expands to target eight different browsers, more than thirty crypto wallet extensions, seven password managers, and eight standalone wallets. Shell history and saved FTP logins are also included.
All stolen data is packed into a ZIP file and then sent to an attacker-controlled Telegram bot. Most components of the malware then delete themselves, using fake timestamps to hide traces. However, one component is left behind: ClickLock installs a modified version of GSocket, an open-source tool that masquerades as an iCloud-related process. This provides the attacker with a persistent backdoor to your Mac.
Who is ClickLock aimed at?
According to researchers, the malware has been active since May 2026. With more than 100 victims in 33 countries, more than half are in Europe. The remaining attacks are aimed at North America, the Middle East and Africa. Although the malware broadly targets crypto wallets and password managers, crypto owners in particular appear to be the main targets.
How to protect your Mac from ClickLock
Apple recently added additional security to macOS for these types of attacks. macOS Tahoe 26.4 displays a warning when you paste a command into Terminal.
But the protection is not infallible. It currently only covers the standard Terminal app, not third-party alternatives like iTerm, for example, and Apple hasn’t specified exactly which commands trigger the popup.

It is advisable never to paste a command into Terminal if a website explicitly asks for it!
If your Mac unexpectedly closes apps and a password window pops up without entering anything. Instead, press and hold the power button to force shut down your Mac, then boot into safe mode to investigate this issue.
Install virus scanner?
Although Macs are known for their strong security, installing a virus scanner is still wise for several reasons:
- Protection against malware: There are indeed viruses and malware that specifically target macOS. A virus scanner can help detect and remove these threats.
- Preventing spread: Even if a virus doesn’t directly affect macOS, it can spread to other devices on your network, such as Windows computers.
- Phishing and ransomware: A good virus scanner can help detect phishing attacks and ransomware, which are becoming increasingly common.
- Real-time security: Virus scanners often provide real-time protection that detects potential threats before they can cause damage.
- Updates and new threats: Cyber threats are constantly evolving, and a virus scanner with regular updates will help protect your system against new threats.
- Peace of mind: A virus scanner offers an extra layer of protection and ensures that you have to worry less about the security of your data.
In short, using a virus scanner on a Mac is a sensible way to protect your system from potential risks.
For an affordable virus scanner you can contact Intego. Intego is a developer of antivirus specially made for macOS. For €2 per month you can protect all your Mac against malware and you can try Intego ONE for free first.
![]() |
Category: Anti Virus Valuation: Developer: Intego From €2 per month |
