Connect with us

CyberSecurity

New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password

Published

on

ClickLock macOS stealer

Meet ClickLock: A Stealer That Won’t Take No for an Answer

Imagine trying to work on your Mac, and every app you open closes itself within a fraction of a second. That’s the nightmare ClickLock inflicts on victims who refuse to hand over their login password.

This new ClickLock macOS stealer doesn’t just steal files silently. It uses a brutal, almost theatrical approach: kill every app in sight, over and over, until the user types their password into a fake system dialog. The malware even sets a precise 210-millisecond timer between kills — fast enough to make the Mac virtually unusable.

Security researchers at SentinelOne first documented the threat, noting how it targets macOS users with a surprisingly simple yet effective social engineering trick.

How the Attack Unfolds

The infection starts not with a malicious app, but with a command. Victims are tricked into pasting a script into Terminal — a common tactic in social engineering campaigns. The script immediately presents a fake system dialog asking for the user’s password.

If the user complies, the stealer grabs the credentials and likely exfiltrates them. But if the user clicks cancel? That’s when the punishment begins.

The 210ms Kill Loop

ClickLock installs two LaunchAgents — persistence mechanisms that ensure it runs at every login. Then it quietly exits. On the next login, the malware springs to life. Finder, Dock, Spotlight, Terminal, Activity Monitor — every essential app gets killed in a continuous loop.

The 210ms interval is key. It’s fast enough to prevent the user from opening a single app, yet slow enough to feel deliberate. The message is clear: type your password, or your Mac becomes a brick.

Why This Malware Is Different

Most infostealers operate silently, hoping to avoid detection. ClickLock takes the opposite approach. It draws attention to itself, using denial-of-service as leverage.

This is a psychological attack as much as a technical one. The victim isn’t just losing data — they’re losing control of their machine in real time. The pressure to give in and type the password becomes almost irresistible.

Researchers note that the fake dialog is designed to look exactly like macOS’s native password prompt. Even savvy users might hesitate before recognizing it as a phishing attempt.

How to Protect Yourself from ClickLock

Defending against this threat requires a combination of caution and technical hygiene. Here’s what you can do:

  • Never paste unknown commands into Terminal. If a website, email, or message asks you to run a script, treat it as a red flag.
  • Check for LaunchAgents. Look in ~/Library/LaunchAgents and /Library/LaunchAgents for unfamiliar plist files. ClickLock installs two of them.
  • Keep your Mac updated. Apple regularly patches security flaws, so running the latest macOS version helps.
  • Use a reputable antivirus tool. SentinelOne and other security suites can detect and block known stealer signatures.
  • Enable FileVault. Full-disk encryption adds a layer of protection even if credentials are compromised.

What to Do If You’re Already Infected

If your Mac starts killing apps after login, don’t panic. Boot into Safe Mode (hold Shift during startup), which prevents LaunchAgents from running. Then remove the malicious plist files and delete the source script. A malware scanner can help clean up any remnants.

After removal, change your Apple ID password and enable two-factor authentication. The attacker may have already captured credentials, so assume the worst and secure your accounts.

The Bigger Picture: macOS Malware Is Getting More Aggressive

ClickLock is part of a troubling trend. macOS malware has traditionally been less common than Windows threats, but that’s changing. Attackers are increasingly targeting Mac users with sophisticated social engineering and aggressive tactics.

This stealer’s approach — using app-killing as coercion — shows how far attackers will go to obtain a single password. It’s a reminder that the human element is often the weakest link in cybersecurity.

For more on protecting your digital life, check out our guide on macOS security best practices and learn how to spot phishing attempts on Mac.

Stay vigilant, and remember: no legitimate system dialog will ever ask you to paste a command into Terminal. If something feels off, it probably is.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

CyberSecurity

Meta Names Assaf Keren as New CISO, Ending a 13-Year Era Under Guy Rosen

Published

on

Meta CISO Assaf Keren

A New Security Chief for the Social Media Giant

Assaf Keren is taking over as the Chief Information Security Officer of Meta, the company confirmed on Wednesday. He steps into a role that has been vacant since Guy Rosen, Meta’s first CISO, announced his retirement in June after a 13-year run with the company.

Keren’s appointment lands at a pivotal moment. Meta is pouring resources into frontier AI development, and the company’s security posture is being tested on a scale few other organizations can comprehend. Billions of users, one platform, and an attack surface that keeps growing.

From PayPal to Qualtrics to Meta

Keren doesn’t come to Meta without baggage — the good kind. His last stop was Qualtrics, where he served as SVP and Chief Security Officer. He joined the experience management software firm in March 2024, but his roots run deeper in the payments world.

Before Qualtrics, Keren spent nine years at PayPal, climbing through a wide range of leadership roles that eventually landed him in the CISO chair. That mix of payments security and enterprise software experience gives him a rare vantage point — he’s seen both the compliance-heavy world of financial services and the faster-moving enterprise SaaS space.

Why This Hire Matters for AI Security

Keren’s own words hint at where his priorities lie. In a statement announcing the move, he framed the challenge around AI trust infrastructure:

“Building AI at the frontier means building the trust infrastructure for it at the same frontier, with the same seriousness, at a scale that touches billions of people. There are few places in the world where that problem is bigger, harder, or more consequential.”

He added that the role combines everything he’s worked on throughout his career — security, systems, and the human side of earning confidence. That last part matters. Security leadership at Meta isn’t just about firewalls and threat intel; it’s about maintaining user trust in an environment where every misstep becomes front-page news.

The Guy Rosen Legacy

Rosen leaves big shoes to fill. He was appointed Meta’s first CISO in 2022, but his history with the company goes back much further. For years, he led product security and integrity efforts, helping Meta navigate everything from election interference to content moderation crises.

His retirement marks the end of an era. Rosen hasn’t confirmed any plans to join another company, though he’s indicated he’ll stay active as an advisor to leaders and organizations. That’s a loss for Meta’s internal bench, but a gain for the broader security community.

What Security Leaders Can Learn From This Transition

Meta’s CISO handoff offers a few lessons for security teams everywhere:

  • Succession planning pays off. Rosen’s departure was announced in June, giving Meta months to find the right replacement rather than scrambling.
  • Cross-industry experience is valuable. Keren’s path through payments and SaaS — not just social media — brings a broader threat model perspective.
  • AI security is becoming a CISO-level issue. Keren’s focus on AI trust infrastructure signals where the industry is heading.

For those keeping tabs on the broader cybersecurity leadership landscape, this appointment is one of several recent moves worth watching. The industry has seen a wave of high-profile CISO transitions lately, and each one reshapes the competitive dynamics at the top.

The Road Ahead for Meta’s Security Team

Keren inherits a security organization that’s both mature and under constant pressure. Meta operates at a scale where even small vulnerabilities can have outsized impact, and the regulatory environment around data protection and AI is only getting stricter.

His background suggests he’ll take a systems-oriented approach — thinking about security not as a series of isolated controls but as an integrated layer across Meta’s products. That’s exactly the mindset needed for the AI era, where model security, data governance, and application security are increasingly intertwined.

One open question: how will Keren shape Meta’s approach to external security research and disclosure? Rosen was known for maintaining a robust bug bounty program and strong ties with the researcher community. Early signs suggest Keren values that kind of collaboration, but only time will tell if he changes the playbook.

For now, the appointment is official. Keren is in. Rosen is out. And Meta’s security team has a new leader at a moment when the stakes have never been higher.

For more on recent moves in the industry, check out our coverage of other CISO appointments and security leadership changes. You can also follow the latest in enterprise security news and hiring announcements.

Continue Reading

CyberSecurity

TELEPUZ Malware Hits the Scene: ClickFix Lures Deliver Modular Data-Stealing Threat

Published

on

TELEPUZ malware

Meet TELEPUZ: A New Modular Threat on the Block

Cybersecurity researchers have flagged a fresh modular malware strain called TELEPUZ that’s been riding the coattails of ClickFix lures on compromised websites since late April 2026. It’s not the flashiest name, but the threat is real — and it’s designed to do serious damage.

Elastic Security Labs researcher Cyril François broke down the findings in a technical report, describing TELEPUZ as “full-featured, lightweight, and modular.” That’s a dangerous combo. It means the malware packs a punch without being bloated, and its modular design lets attackers swap in new capabilities on the fly.

Here’s the kicker: while the number of command-and-control (C2) domains is currently small, the daily evolution of the infrastructure suggests this thing is scaling up fast. Early days, but the trajectory is worrying.

How ClickFix Lures Work: The Entry Point

ClickFix isn’t new, but it’s become a favorite social engineering trick. Attackers inject fake error prompts or CAPTCHA-style popups into compromised websites. When a visitor clicks, they’re instructed to copy a malicious payload and paste it into a terminal or PowerShell window. Boom — the malware gets a foothold.

In TELEPUZ’s case, the lures are embedded in sites that have already been hacked. The user thinks they’re solving a CAPTCHA or fixing a browser error. Instead, they’re executing a command that downloads the malware straight onto their machine.

It’s a low-friction attack. No phishing email, no malicious attachment — just a convincing popup on a site the victim already trusts.

What TELEPUZ Does Once It’s In

TELEPUZ isn’t a one-trick pony. According to François’s analysis, the malware is built to do two main things: steal data and run remote commands. But the modular architecture means those are just the starting points.

Data Theft Capabilities

The malware is designed to harvest sensitive information from infected systems. That could include credentials, browser cookies, or other valuable data. The lightweight design means it can run quietly in the background without drawing too much attention.

Remote Command Execution

Beyond theft, TELEPUZ can execute commands sent from its C2 servers. This gives attackers a direct line into the infected machine, letting them move laterally, drop additional payloads, or wreak havoc in real time.

The modular nature is what makes this particularly sneaky. Attackers can add new modules as the campaign evolves, meaning the threat landscape could shift quickly.

Infrastructure: Small Now, Growing Fast

François noted that the C2 infrastructure is currently limited to a small number of domains. But that’s not a reason to breathe easy. The daily changes in infrastructure signal active development and expansion.

This is a campaign that’s still in its early innings. Security teams should expect the C2 count to grow, and the attack methods to evolve as the operators refine their playbook.

Protecting Yourself Against ClickFix and TELEPUZ

So what can you do? The attack vector relies on social engineering, so awareness is your first line of defense.

  • Think before you click: If a website asks you to copy-paste a command into your terminal or PowerShell, stop. Legitimate sites don’t do that.
  • Keep your browser updated: Many ClickFix lures exploit browser vulnerabilities. Patching those closes the door.
  • Use endpoint detection tools: Security solutions that monitor for unusual command execution can catch TELEPUZ before it takes hold.
  • Verify site integrity: If a trusted site suddenly shows odd popups, it might be compromised. Leave and report it.

For security teams, the takeaway is to stay vigilant. The modular malware trend is growing, and TELEPUZ is the latest example. Monitoring C2 domains and watching for ClickFix lures on your users’ frequently visited sites can help you stay ahead.

The Bottom Line on TELEPUZ

TELEPUZ is a reminder that cyber threats keep getting more sophisticated. It’s lightweight, modular, and spreading through a social engineering trick that’s hard to spot. The small C2 footprint today could be a full-blown botnet tomorrow.

Stay sharp out there. And next time a website tells you to paste a command into your terminal — just say no.

Continue Reading

CyberSecurity

Upbound Group’s Data Breach Led to $13 Million in Fraudulent Contract Losses

Published

on

Upbound Group data breach

Upbound Group Data Breach: The $13 Million Question

When hackers broke into Upbound Group’s systems, they didn’t steal credit card numbers or social security details. They took something arguably more valuable: the keys to the company’s own lending operation.

The Texas-based consumer finance firm, best known for Rent-A-Center, Acima, and Brigit, disclosed in a Securities and Exchange Commission (SEC) filing that cybercriminals recently obtained non-sensitive customer information and other documents. The company believes that stolen data was then weaponized to approve fraudulent lease-to-own agreements, driving losses of roughly $13 million in its Acima segment during the second quarter of 2026.

It’s a stark reminder that a breach’s real cost isn’t always the data itself. It’s what the data enables.

How Stolen Data Fueled Lease-to-Own Fraud

Upbound’s business model relies on offering flexible payment solutions to consumers who might not qualify for traditional credit. That makes its customer database a goldmine for fraudsters. With enough personal details — even non-sensitive ones — criminals can piece together a convincing identity.

According to the filing, the stolen information was “subsequently used to facilitate fraudulent lease-to-own agreements.” Essentially, the attackers used real customer data to open new accounts or take over existing ones, walking away with merchandise and leaving Upbound holding the bill.

The company has alerted law enforcement and brought in external cybersecurity experts to harden its defenses. Its investigation remains ongoing, but Upbound currently assesses the incidents as not material to its overall financial health.

That’s a notable stance, given the dollar figure attached. But for a company of Upbound’s size, $13 million — while painful — may not be a existential threat.

The Acima Segment’s Exposure

All eyes are on Acima, Upbound’s virtual lease-to-own arm. Unlike Rent-A-Center’s brick-and-mortar presence, Acima operates through retail partners, which means more digital touchpoints and, potentially, more vulnerability.

The breach’s impact was concentrated there, suggesting the attackers targeted a specific workflow or data repository tied to Acima’s underwriting process. The company hasn’t shared technical details about how the intrusion occurred or which systems were accessed.

Who’s Behind the Attack?

So far, no known cybercrime group has claimed responsibility. Upbound hasn’t appeared on any major leak site, which is unusual. Ransomware gangs typically rush to publicize their victims to pressure them into paying.

That silence could mean a few things. The attackers may be purely financially motivated and quietly exploiting the stolen data rather than seeking a ransom. Or they could be a smaller, less visible operation that prefers to stay under the radar.

It’s also possible the investigation is still uncovering the attack’s full scope. These things often take months to untangle.

Industry Context: A Growing Trend of Data-Driven Fraud

This incident isn’t happening in a vacuum. Fraudsters are increasingly using stolen data to commit synthetic identity fraud and account takeover, particularly in the financial services sector.

The lease-to-own industry is especially attractive because approvals are often faster and less rigorous than traditional bank loans. That speed is a feature for legitimate customers, but it’s a bug when criminals have the right data.

Related incidents show how widespread this problem has become. Suno, Paidwork data breaches affect tens of millions of accounts, demonstrating the sheer scale of credential exposure. And a ransomware group threatening to leak data stolen from Coca-Cola’s Fairlife shows that even major brands aren’t immune to extortion attempts.

What This Means for Consumers and Businesses

For Upbound customers, the immediate risk is relatively low — the company says the stolen data was non-sensitive. But that’s cold comfort. Even basic information like names, addresses, and account details can be used in social engineering attacks.

Here’s what consumers should watch for:

  • Unexpected lease-to-own accounts opened in their name
  • Collection notices for merchandise they never received
  • Phishing emails referencing Upbound, Rent-A-Center, or Acima
  • Credit report inquiries from unfamiliar lenders

For businesses, the lesson is clear: data you consider low-value can be high-value to a criminal with imagination. The new index tracking material breaches — which refuses to add up the losses — is a useful resource for professionals trying to understand the real-world impact of these events.

The Bottom Line on the Upbound Group Data Breach

Upbound’s $13 million loss is a case study in how cybercrime has evolved. Attackers aren’t just after credit cards anymore. They’re after the operational data that lets them commit fraud at scale.

The company’s decision to disclose the breach and its financial impact is commendable, even if the news is uncomfortable. As the investigation unfolds, more details may emerge about how the attackers got in and whether other segments were affected.

For now, the key takeaway is that data breaches have consequences that extend far beyond the initial intrusion. Sometimes, the real damage happens months later, when stolen information is quietly used to approve fraudulent contracts.

And that’s a cost no balance sheet can easily absorb.

Continue Reading

Trending