www.malwarebytes.com 7/21/2026, 12:31:06 PM · external

ClickLock Stealer hijacks Macs with Cloudflare password prompts

ClickLock Stealer hijacks Macs with Cloudflare password prompts
CyberSIXT Evidence Panel Source marked as original reporting

THE article discusses the newly discovered ClickLock Stealer, a macOS infostealer designed to lock a victim's Mac until they provide their password. Delivered through phishing pages resembling Cloudflare verification, the malware utilizes a shell script to trick users into entering commands that lead to their own infection.

Once installed, it steals sensitive information such as macOS passwords, browser data, and cryptocurrency wallet information, while also installing a persistent backdoor using the GSocket toolkit for continued access. If victims refuse to comply with the fake password prompt, the malware enacts a 'kill loop' that disables key processes, making the system unusable until the password is provided.

The article also provides safety tips for Mac users, urging caution around untrusted instructions, secure device usage, and maintaining awareness of evolving cyber threats.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline