Threat Intelligence Very Bearish 6

100 Systems in 33 Nations Hit by Mac Malware That Locks Apps, Steals Passwords

ClickLock, a new macOS malware spreading via fake 'verify you are human' pages, has compromised over 100 systems across 33 countries since May 2026, using app-locking extortion to steal credentials and install backdoors. Cybersecurity experts warn it's a novel approach that bypasses traditional detection.

· 4 min read ·
Share

Key Takeaways

  • ClickLock, a new macOS malware spreading via fake 'verify you are human' pages, has compromised over 100 systems across 33 countries since May 2026, using app-locking extortion to steal credentials and install backdoors.
  • Cybersecurity experts warn it's a novel approach that bypasses traditional detection.

Mentioned

ClickLock technology Group-IB company Apple company AAPL VirusTotal company Telegram product

Key Intelligence

Key Facts

  1. 1First spotted on VirusTotal on June 9, 2026, with zero security vendor detections at the time.
  2. 2Active since May 2026; has compromised over 100 systems in 33 countries.
  3. 3Uses a fake 'verify you are human' page to trick users into executing a Terminal command that downloads malware.
  4. 4Locks applications (Finder, browsers) repeatedly until the user enters their macOS password, enabling credential theft.
  5. 5Steals saved passwords, browser data, and cryptocurrency wallet files; installs a persistent remote access backdoor.
  6. 6Discovered by Group-IB researchers, who published their findings amid low detection rates by traditional antivirus.
Systems Compromised
100+ since May 2026

Campaign active across 33 countries

Analysis

For cybersecurity professionals, ClickLock represents a dangerous evolution in Mac-targeted threats. By combining social engineering with a seemingly legitimate macOS user interface element, it co-opts the user into compromising their own system, making endpoint protection and user training critical.

A new Mac malware campaign discovered by Group-IB researchers employs a uniquely coercive social engineering technique to compromise macOS systems. Dubbed ClickLock, the malware lures users through a fake “verify you are human” webpage that instructs them to copy and paste a command into Terminal. Once executed, a convincing progress bar appears while the script silently downloads and installs malicious software. The attack then presents what looks like a legitimate macOS password dialog; if the user cancels, the malware will repeatedly quit Finder, browsers, and other applications, rendering the Mac nearly unusable until the login password is entered. This extortion-like behavior—locking apps until the user surrenders credentials—is a hallmark of ClickLock.

For cybersecurity professionals, ClickLock represents a dangerous evolution in Mac-targeted threats.

The malware’s objectives go beyond credential harvesting. Once installed, ClickLock searches for saved passwords, browser data, and cryptocurrency wallet files, and deploys a hidden backdoor that allows attackers to remotely reconnect and control the infected machine. According to Group-IB, the threat has been active since at least May 2026 and has already hit over 100 systems across 33 countries, suggesting a broad and deliberate targeting campaign. The malicious script was first uploaded to VirusTotal on June 9, 2026, yet at the time of analysis, none of the platform’s integrated security engines flagged it as malicious—highlighting its ability to evade signature-based detection.

ClickLock follows a growing trend of malware that exploits user trust in system interfaces rather than relying on purely technical exploits. In this case, the attack chain mimics a legitimate CAPTCHA verification, a familiar web element, and then abuses the Terminal, a powerful command-line tool that average users rarely interact with. By instructing the victim to run a command, the attacker effectively bypasses macOS Gatekeeper and code-signing checks, as the command executes directly within the user’s session. The use of an app-locking mechanism to apply pressure is a psychological twist: many users, frustrated and unable to work, will comply and enter their password, unwittingly handing over the keys to their digital lives. This technique is reminiscent of previous “scareware” or “ransomware” tactics but applied in a more subtle, non-encrypting manner to steal credentials and install persistence.

The implications for both consumers and enterprises are significant. For individuals, ClickLock poses a direct threat to personal data, including online banking credentials, email accounts, and cryptocurrency holdings. The theft of crypto wallet files is particularly troubling, as hot wallets store private keys and can lead to immediate and irreversible financial loss. For organizations, any infected Mac could act as a beachhead for lateral movement, corporate espionage, or ransomware deployment, especially given the backdoor’s remote-control capabilities. With macOS’s growing market share in enterprise environments (partly driven by employee choice programs), the attack surface for such threats is expanding. Moreover, the campaign’s detection by a cybersecurity firm rather than by built-in defenses underscores the need for layered security, including endpoint detection and response (EDR) solutions and proactive threat intelligence.

What to Watch

Looking ahead, ClickLock is unlikely to be an isolated incident. The success of social-engineering-based command execution on macOS will inspire copycat campaigns and variations targeting other operating systems. Apple may respond by introducing more explicit warnings when Terminal or similar utilities are launched via external prompts, but the fundamental problem is that users can be manipulated into voluntarily compromising their own security. Education and awareness are crucial; users must be trained never to copy and paste commands from unknown sources, no matter how legitimate the request appears. For security teams, monitoring unusual Terminal execution patterns and deploying application control policies can help mitigate the risk.

In the broader context of Mac malware evolution, ClickLock represents an escalation. While past threats like Silver Sparrow or XCSSET exploited development tools and supply chains, this new strain relies purely on human gullibility and a coercive user experience. Its low detection rate on VirusTotal at upload time indicates that traditional antivirus may struggle to keep pace with novel delivery methods. The cybersecurity community will need to develop behavioral analytics that can spot anomalous command-line activity and fake system prompts. As the campaign continues to evolve, the next few months will reveal whether ClickLock is a one-off blitz or the start of a sustained trend in cross-platform social engineering attacks. For now, Mac users should be on high alert for any web page asking them to open Terminal—no CAPTCHA should ever require that.

Timeline

Timeline

  1. Campaign begins

  2. First VirusTotal upload

  3. Public disclosure

Cite This Page

"100 Systems in 33 Nations Hit by Mac Malware That Locks Apps, Steals Passwords." Cyber Intelligence Brief, July 27, 2026. https://getcyberbrief.com/story/clicklock-mac-malware-cyber-threat

How we covered this story

Every story in our cybersecurity coverage is assembled from multiple primary sources, cross-referenced for factual consistency, and scored along three independent dimensions: sentiment, operational impact, and source-cluster confidence. Single-source rumors and unverifiable claims do not pass our editorial gate. When a story shows "Verified by N sources" with N≥2, the development is independently corroborated; when N=1, we mark it explicitly so readers can weigh the signal accordingly.

Impact scoring uses a 1-10 scale weighted toward regulatory, financial, and operational consequence rather than coverage volume. A topic that runs in every outlet but moves no real decisions ranks lower than a niche regulatory filing that reshapes how operators in the cybersecurity space have to behave. Read our full methodology for the scoring rubric, our glossary for term definitions, and our trends index for the longitudinal view across the beat.

Sources are only linked to a story once they clear our classification pipeline at a minimum 35 percent relevance threshold. According to that methodology, reviewed July 2026, this follows multi-source corroboration standards recommended by journalism research bodies such as the Reuters Institute for the Study of Journalism.

See something wrong in this story — a wrong fact, a broken source link, a misattributed entity? Report a data issue.