ClickLock macOS Information-Stealing Malware
First seen Jul 17, 2026 · Updated Jul 17, 2026
ClickLock is a newly identified macOS information-stealing malware that forcibly terminates all visible user processes to coerce victims into entering their system login password. Once captured, this password can be used to unlock keychains, decrypt stored credentials, and gain deeper system access. The technique represents an evolution in macOS malware social engineering, exploiting user trust in system prompts.
Technical Analysis
ClickLock operates by killing all visible foreground processes and windows, creating a disorienting environment where the only apparent recovery action is to enter the macOS login password into a spoofed system dialog. This password is then exfiltrated and can be leveraged to unlock the macOS Keychain, decrypt saved browser credentials, SSH keys, and application tokens stored locally. The malware likely relies on AppleScript, osascript-based fake system prompts, or accessibility API abuse to simulate legitimate OS-level authentication requests, a technique seen in prior macOS stealers like Atomic Stealer and Realst. No CVE has been assigned as this abuses legitimate OS behavior and social engineering rather than a software vulnerability. For organizations running AI agents or LLM tool-use frameworks on macOS developer workstations, credential theft via ClickLock could expose stored API keys, cloud service tokens, and local secrets used by agent orchestration tools, enabling downstream compromise of connected AI pipelines and services.
Affected Systems
macOS devices (versions unspecified in source reporting), particularly developer and enterprise workstations with Keychain-stored credentials, browser-saved passwords, and locally cached API tokens
Indicators of Compromise
- Specific hashes, C2 domains, and file names not disclosed in available reporting
Remediation Steps
- 1
User Awareness Training
Educate users never to enter system passwords into unexpected full-screen prompts, especially after unusual application terminations.
- 2
Enable macOS Gatekeeper and XProtect
Ensure built-in macOS malware protections are enabled and signature definitions are up to date.
- 3
Restrict Accessibility Permissions
Audit and limit apps with Accessibility and Automation permissions, which can be abused to control UI elements and simulate system dialogs.
- 4
Rotate Credentials and API Keys
If compromise is suspected, immediately rotate Keychain-stored passwords, browser credentials, SSH keys, and any API tokens used by local AI agent or automation tools.
- 5
Deploy EDR for macOS
Use endpoint detection tools capable of identifying anomalous process termination patterns and fake system dialog generation.
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.