ClickLock macOS malware kills apps every 210ms for your password

A new macOS infostealer discovered by Group-IB bombards victims with app closures every 210 milliseconds until they type their login password.

AppleThreat Staff
2 Min Read

Group-IB researchers have uncovered ClickLock Stealer, a new macOS infostealer that uses an aggressive app-killing loop to coerce victims into typing their login password. The malware arrives when a user is tricked into pasting a command into Terminal, often through fake Cloudflare CAPTCHA pages in a ClickFix social engineering scheme.

Once executed, the script presents a fake system password prompt. If the victim cancels, ClickLock silently installs two LaunchAgents into ~/Library/LaunchAgents/. At the next login, the malware begins killing Finder, the Dock, Spotlight, Terminal, Activity Monitor, and major browsers every 210 milliseconds in a loop that can run for up to 83 hours. The only thing left on screen is a password dialog, and the desktop stays frozen until the victim types their credentials.

Submitting the password gives the attacker the macOS login credential, Chrome’s Safe Storage AES key, browser cookies, saved passwords, crypto wallet extensions, Keychain contents, shell history, and FileZilla server credentials. Group-IB estimates at least 100 victims across 33 countries since May, with more than half in Europe. The malware’s orchestrator script had zero detections on VirusTotal when first analyzed on June 9.

Group-IB advises anyone who may have been compromised to revoke active browser sessions immediately, treat every saved password and wallet key as compromised, and change credentials from a clean device.

Share This Article