This Malware Kills Your Apps 5 Times a Second Until You Give Up Your Password
A new macOS malware is tricking users into revealing their passwords through social engineering. Called ClickLock, it targets Macs with fake verification pages that mimic ClickFix campaigns, which pose as troubleshooting assistance to con people into installing harmful software.
Cybersecurity assessment firm Group-IB found that ClickLock prompts users to run a command in Terminal to fix purported browser or security issues. Once the user runs the command, the malware downloads its components, sets up LaunchAgents for persistence, and then starts disabling normal system functions.
Analysts say ClickLock repeatedly kills visible applications every 210 milliseconds, including Finder, browsers, system tools, and more, making the desktop almost unusable. It can also display a macOS‑style password prompt with the victim’s real username, making the dialog appear legitimate. If the user tries to cancel the prompt or enters the wrong password, the loop will continue, even after a restart, until the correct password is entered. Once the password is correct, ClickLock forwards it to attackers over Telegram and uses it to unlock macOS Keychain.
ClickLock collects data from eight web browsers, some cryptocurrency wallet extensions, password managers, FTP clients, and shell histories, then sends it to attackers. Reports say more than 100 victims across 33 countries have surfaced so far, with most cases in Europe. And the malware continues to evolve.
To be safe, don’t copy Terminal commands from any website, and be wary of constant login prompts or repeated rapid app crashes.