New ClickLock macOS malware traps users into revealing login password

MacOS Malware Traps Users into Revealing Login Passwords in Elaborate Social Engineering Scheme

A new piece of macOS malware has been discovered to be secretly infiltrating users’ computers, forcing them to reveal their login passwords through a complex social engineering technique. The malware, dubbed ClickLock, has already infected at least 100 systems across 33 countries since May, and its operators are using it to steal sensitive information such as cryptocurrency assets, login credentials, and password-manager data.

ClickLock works by initially displaying a fake macOS password dialog, using the victim’s real username and a downloaded Apple icon. If the user enters their password, the malware validates the data and exfiltrates it to the attacker via Telegram. However, if the user cancels the dialog, the malware establishes persistence through two macOS LaunchAgents that reload at the next login.

The malware then runs a termination loop every 210 milliseconds, targeting key apps such as Finder, Dock, Terminal, Activity Monitor, Console, System Settings, Spotlight, and web browsers. This loop continues for 300,000 seconds (approximately 83 hours) or until the victim supplies a correct password. The second LaunchAgent runs a separate coercion mechanism that also terminates system applications and requests Keychain authorization via a legitimate system prompt.

In addition to forcing users into revealing their login passwords, ClickLock also deploys a data-harvesting module that targets sensitive information from eight browsers, cryptocurrency wallet extensions, desktop wallet files, encrypted vault material, password-manager extension data, cached cryptocurrency addresses, shell histories, and basic system information. The harvested data is then packaged into a ZIP archive and uploaded via the Telegram Bot API.

What’s particularly concerning about ClickLock is its ability to persist on infected systems through multiple methods, including LaunchAgents, crontab entries, and modifications to shell configuration files. This means that even if users manage to remove the malware, it can still re-establish itself at the next login.

The researchers who discovered ClickLock warn that its operators are using social engineering tactics to trick victims into revealing their login passwords, rather than relying on exploits or elevated privileges. This highlights the importance of being cautious when interacting with any system prompts or dialogs, especially those that appear suspicious or out of place.

To avoid falling victim to ClickLock and similar malware, users should be vigilant when encountering unfamiliar prompts or dialogs, and never enter sensitive information unless they are absolutely sure it’s legitimate. Additionally, keeping macOS up-to-date with the latest security patches is crucial in preventing such attacks.


Source: Bleeping Computer — 2026-07-16