logo

New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password

ID: f7408c6e-260d-50b0-8430-76b2afbcb061

STIX ID: report--f7408c6e-260d-50b0-8430-76b2afbcb061

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-07-16

Date Updated: 2026-07-18

Author: [email protected] (The Hacker News)

...
...

**ClickLock Stealer — macOS infostealer using coercive UI kill-loops:** ClickLock is delivered via a pasted Terminal command (ClickFix front-end) that, if the victim cancels a fake password dialog, installs LaunchAgents that repeatedly kill Finder, Dock and other UI processes until the user types their password; successful runs yield macOS login passwords, Chrome Safe Storage keys, browser credentials and cookies, crypto wallet files, and a GSocket-derived backdoor communicating via relays and Telegram bots. Group-IB reports ~100 targets across 33 countries, low detection on VirusTotal, and recommends powering off, booting into Safe Mode, revoking sessions and rotating credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.