Apple device users often argue that they don’t need antivirus protection, as malware is “a Windows problem.” However, the newly discovered ClickLock scam that’s moving through Europe is proving that Apple products aren’t immune to cyberattacks.
Researchers at Group-IB just published findings on a new operation that doesn't rely on a clever exploit or a hidden backdoor buried in a fake update to steal information. Instead, hackers are using deception and persistence to trick users into giving away valuable credentials. Essentially, they’re annoying users into handing over their passwords.
The ClickLock Scam Is a Different Kind of Attack
Unlike cyberattacks that exploit software vulnerabilities, the ClickLock scam focuses on manipulation. Security researchers found that this campaign creates an incredibly frustrating experience, making the computer functionally useless until the victim gives in.
Attacks typically begin when the victim is tricked into copying and running a malicious command in Terminal (often via a fake Cloudflare/ClickFix verification page). That command then repeatedly forces key macOS applications to close every fraction of a second. Finder, Dock, Terminal, and other essential apps are constantly terminated, making the computer difficult or even impossible to use normally. At the same time, a password prompt continues appearing on the screen.
Because the device becomes so disruptive to use, many people may assume the prompt is legitimate and enter their password simply to make the interruptions stop. The ClickLock macOS stealer succeeds because it creates urgency rather than relying on technical sophistication.
These attacks try to frustrate users so they ignore their normal security behaviors. The repeated fake verification prompt is convincing enough that some users may believe macOS needs authentication to fix the problem. When dealing with an unusable computer, many people will just enter their password to make the chaos stop, putting it right into the hackers’ hands.
This combination of relentless disruption and convincing prompts makes the campaign a serious macOS security threat, even though it does not rely on traditional malware techniques.
Protecting Your Company From This macOS Security Threat
ClickLock Scam is designed for credential theft, specifically targeting Apple user passwords. Once criminals obtain those credentials, they may gain access to business accounts, cloud storage, email, or other sensitive resources connected to the device.
Even businesses that follow good cybersecurity practices may be vulnerable if employees aren’t prepared for a social engineering attack like this one. Traditional antivirus tools are built to catch malicious files, not social engineering loops disguised as system prompts.
To address this issue, train staff on how to respond if their Mac suddenly starts acting erratically, with apps closing on their own, windows disappearing, or a sudden password prompt. The right move is to disconnect the device from the network and shut it down or seek IT assistance, not comply with the prompt.
Other protections include:
- Keeping macOS updated
- Using strong passwords
- Enabling multi-factor authentication
- Reporting unusual activity
Regular cybersecurity awareness training can help staff recognize suspicious prompts like the ClickLock scam before sensitive information is exposed. Even if you use Apple devices, investing in security protection is critical to keeping your company on track.

(724) 356-4070 



