Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

Security alert graphic for ClickLock macOS info-stealer malware with ACTION REQUIRED label

New macOS Malware Kills Your Apps Until You Hand Over Your Password

A new strain of macOS malware called ClickLock is targeting Mac users with a brutally simple tactic: it terminates every visible app — Finder, browsers, Terminal, even Activity Monitor — every 210 milliseconds until you type your login password into a fake dialog box.

ClickLock doesn’t exploit a macOS vulnerability. It exploits the assumption that Macs don’t need the same endpoint protection as Windows. If your business runs unmanaged Macs, read on.

How It Gets In

The attack starts with a ClickFix-style social engineering lure — a fake error page or Cloudflare verification prompt that convinces you to paste a command into Terminal. That command installs two persistence agents and waits quietly. At your next login, the lockout begins: every app dies on a loop for up to 83 hours, leaving nothing but a password dialog on a dead desktop.

Type your password, and ClickLock raids your Keychain, browser-saved credentials, and cryptocurrency wallets across 31 browser extensions and 8 desktop apps. Group-IB has tracked at least 100 victims across 33 countries since May.


Why This Matters for Australian Businesses

In most SMB environments we manage across Sydney, the Central West and Brisbane, Windows endpoints run EDR and get patched on schedule. Macs often don’t. They sit outside the endpoint management baseline because “Macs don’t get viruses.” ClickLock is a case study in why that assumption is now genuinely dangerous — the malware sidesteps macOS’s built-in protections entirely through social engineering.


What to Do Now

  • Tell staff: never paste commands into Terminal from a website, email, or support chat. Full stop. This is the single most effective defence against ClickFix-style attacks.
  • Deploy endpoint protection on every Mac, not just Windows devices. If it connects to your network, it needs coverage.
  • Enable macOS Lockdown Mode on high-value machines — executives, finance staff, anyone handling sensitive client data.
  • If a Mac starts killing apps on repeat, disconnect it from the network immediately and call your IT provider. Do not type your password into the dialog.

Are Your Macs Actually Managed?

Most businesses protect their Windows fleet but leave Macs wide open. We can bring your Apple devices into the same endpoint management and security baseline as everything else.


Related Guide

Cybersecurity for Sydney SMBs

Explore our complete guide to protecting your business from cyber threats.

Read the Full Guide →