ClickLock Stealer is a new, modular macOS infostealer delivered via ClickFix-style phishing pages that can lock a victim’s Mac, steal their macOS password, browser and password manager data, cryptocurrency wallets, and then leave behind a persistent backdoor.
The malware was discovered by Group-IB researchers. They named it after the ClickFix distribution technique and its ability to lock a victim’s Mac if they don’t follow its instructions by killing all visible processes.
The researchers found a malicious shell script typically used to trick users into infecting their own device and followed the trail from there. The script first displays a fake Cloudflare progress bar, suggesting it was intended to be used as part of a fake browser verification flow.
Victims land on a phishing page that mimics Cloudflare verification or another fake system utility, similar to those used in the Infiniti Stealer campaign, and later ClickFix attacks impersonating Claude or cleanup utilities.
The page instructs the user to open Terminal, paste a command, and press Return, presenting it as a required “human verification” step or a quick fix.
The researchers explain:
“the malware orchestrates further modules that search the system for various data including browser credentials, password manager data, crypto wallet extensions, desktop wallet files, etc. and even employs a GSocket backdoor.”
This all happens while the user is distracted by fake Cloudflare images.
A GSocket backdoor abuses GSocket (short for Global Socket), an open-source networking toolkit. While designed for legitimate remote administration and penetration testing, attackers can weaponize it to establish stealthy, persistent, encrypted remote access to compromised systems.
Forcing victims to hand over their password
What really stands out is the way the malware forces the user to provide their macOS system’s password.
First, it displays a convincing fake macOS password prompt using the victim’s real username and a downloaded Apple icon. If the user enters their password, it is sent, along with all the previously stolen data, to a Telegram channel controlled by the attackers.
If the user refuses, the malware triggers a loop that shuts down key processes, including Finder, Dock, Terminal, Activity Monitor, Console, System Settings, Spotlight, and all major web browsers. It leaves only a password dialog on the screen until the victim complies.
This “kill loop” runs every 210 milliseconds for up to 83 hours, or until the user enters the correct password. The result is a system that’s essentially unusable, with the password prompt becoming the only interactive element.
Once the stolen data has been sent to the Telegram channel, the malware starts deleting its own modules. However, unlike the infostealer modules, the GSocket backdoor remains installed, giving the attacker ongoing remote access to the system.
That means attackers can return later, even after the stealer components have self‑deleted, to install new malware, steal more data, or move through a corporate network using VPNs or SSH access already available on the compromised Mac.
How to stay safe
Users running macOS Tahoe 26.4 and later will see warnings about possible ClickFix attacks, but everyone should remain cautious.
With ClickFix running rampant and inventing new methods all the time, it’s important to stay aware, think twice before following unexpected instructions, and keep your devices protected.
- Slow down. Don’t rush to follow instructions on a webpage or prompt, especially if it asks you to run commands on your device or copy and paste code. Attackers rely on urgency to bypass your critical thinking.
- Avoid running commands or scripts from untrusted sources. Never run code or commands copied from websites, emails, or messages unless you trust the source and understand what the action does.
- Verify instructions independently. If a website tells you to execute a command or perform a technical action, check through official documentation or contact support before proceeding.
- Limit copy and paste for commands. Manually typing commands instead of copy and paste can reduce the risk of unknowingly running malicious payloads hidden in copied text.
- Secure your devices. Use an up-to-date, real-time anti-malware solution with web protection. Malwarebytes blocks connections to unsafe sites like these.

- Educate yourself on evolving attack techniques. Understanding that attacks may come from unexpected places helps maintain vigilance. Keep reading our blog!
- Stay away from sponsored ads in search results. Anyone can buy them and make them look legitimate.
Pro tip: The free Malwarebytes Browser Guard extension warns you when a website tries to copy something to your clipboard.
We don’t just report on threats—we remove them
Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.




