highMalware

ClickLock macOS Information-Stealing Malware

First seen Jul 17, 2026 · Updated Jul 17, 2026

macosinfostealercredential-theftsocial-engineeringagent-relevant

ClickLock is a newly identified macOS information-stealing malware that forcibly terminates all visible user processes to coerce victims into entering their system login password. Once captured, this password can be used to unlock keychains, decrypt stored credentials, and gain deeper system access. The technique represents an evolution in macOS malware social engineering, exploiting user trust in system prompts.

Technical Analysis

ClickLock operates by killing all visible foreground processes and windows, creating a disorienting environment where the only apparent recovery action is to enter the macOS login password into a spoofed system dialog. This password is then exfiltrated and can be leveraged to unlock the macOS Keychain, decrypt saved browser credentials, SSH keys, and application tokens stored locally. The malware likely relies on AppleScript, osascript-based fake system prompts, or accessibility API abuse to simulate legitimate OS-level authentication requests, a technique seen in prior macOS stealers like Atomic Stealer and Realst. No CVE has been assigned as this abuses legitimate OS behavior and social engineering rather than a software vulnerability. For organizations running AI agents or LLM tool-use frameworks on macOS developer workstations, credential theft via ClickLock could expose stored API keys, cloud service tokens, and local secrets used by agent orchestration tools, enabling downstream compromise of connected AI pipelines and services.

Affected Systems

macOS devices (versions unspecified in source reporting), particularly developer and enterprise workstations with Keychain-stored credentials, browser-saved passwords, and locally cached API tokens

Indicators of Compromise

  • Specific hashes, C2 domains, and file names not disclosed in available reporting

Remediation Steps

  1. 1

    User Awareness Training

    Educate users never to enter system passwords into unexpected full-screen prompts, especially after unusual application terminations.

  2. 2

    Enable macOS Gatekeeper and XProtect

    Ensure built-in macOS malware protections are enabled and signature definitions are up to date.

  3. 3

    Restrict Accessibility Permissions

    Audit and limit apps with Accessibility and Automation permissions, which can be abused to control UI elements and simulate system dialogs.

  4. 4

    Rotate Credentials and API Keys

    If compromise is suspected, immediately rotate Keychain-stored passwords, browser credentials, SSH keys, and any API tokens used by local AI agent or automation tools.

  5. 5

    Deploy EDR for macOS

    Use endpoint detection tools capable of identifying anomalous process termination patterns and fake system dialog generation.

Industries Most Exposed

technologysoftware developmentfinancehealthcareprofessional services

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.