CyberSecurity

New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password

Published

on

Meet ClickLock: A Stealer That Won’t Take No for an Answer

Imagine trying to work on your Mac, and every app you open closes itself within a fraction of a second. That’s the nightmare ClickLock inflicts on victims who refuse to hand over their login password.

This new ClickLock macOS stealer doesn’t just steal files silently. It uses a brutal, almost theatrical approach: kill every app in sight, over and over, until the user types their password into a fake system dialog. The malware even sets a precise 210-millisecond timer between kills — fast enough to make the Mac virtually unusable.

Security researchers at SentinelOne first documented the threat, noting how it targets macOS users with a surprisingly simple yet effective social engineering trick.

How the Attack Unfolds

The infection starts not with a malicious app, but with a command. Victims are tricked into pasting a script into Terminal — a common tactic in social engineering campaigns. The script immediately presents a fake system dialog asking for the user’s password.

If the user complies, the stealer grabs the credentials and likely exfiltrates them. But if the user clicks cancel? That’s when the punishment begins.

The 210ms Kill Loop

ClickLock installs two LaunchAgents — persistence mechanisms that ensure it runs at every login. Then it quietly exits. On the next login, the malware springs to life. Finder, Dock, Spotlight, Terminal, Activity Monitor — every essential app gets killed in a continuous loop.

The 210ms interval is key. It’s fast enough to prevent the user from opening a single app, yet slow enough to feel deliberate. The message is clear: type your password, or your Mac becomes a brick.

Why This Malware Is Different

Most infostealers operate silently, hoping to avoid detection. ClickLock takes the opposite approach. It draws attention to itself, using denial-of-service as leverage.

This is a psychological attack as much as a technical one. The victim isn’t just losing data — they’re losing control of their machine in real time. The pressure to give in and type the password becomes almost irresistible.

Researchers note that the fake dialog is designed to look exactly like macOS’s native password prompt. Even savvy users might hesitate before recognizing it as a phishing attempt.

How to Protect Yourself from ClickLock

Defending against this threat requires a combination of caution and technical hygiene. Here’s what you can do:

  • Never paste unknown commands into Terminal. If a website, email, or message asks you to run a script, treat it as a red flag.
  • Check for LaunchAgents. Look in ~/Library/LaunchAgents and /Library/LaunchAgents for unfamiliar plist files. ClickLock installs two of them.
  • Keep your Mac updated. Apple regularly patches security flaws, so running the latest macOS version helps.
  • Use a reputable antivirus tool. SentinelOne and other security suites can detect and block known stealer signatures.
  • Enable FileVault. Full-disk encryption adds a layer of protection even if credentials are compromised.

What to Do If You’re Already Infected

If your Mac starts killing apps after login, don’t panic. Boot into Safe Mode (hold Shift during startup), which prevents LaunchAgents from running. Then remove the malicious plist files and delete the source script. A malware scanner can help clean up any remnants.

After removal, change your Apple ID password and enable two-factor authentication. The attacker may have already captured credentials, so assume the worst and secure your accounts.

The Bigger Picture: macOS Malware Is Getting More Aggressive

ClickLock is part of a troubling trend. macOS malware has traditionally been less common than Windows threats, but that’s changing. Attackers are increasingly targeting Mac users with sophisticated social engineering and aggressive tactics.

This stealer’s approach — using app-killing as coercion — shows how far attackers will go to obtain a single password. It’s a reminder that the human element is often the weakest link in cybersecurity.

For more on protecting your digital life, check out our guide on macOS security best practices and learn how to spot phishing attempts on Mac.

Stay vigilant, and remember: no legitimate system dialog will ever ask you to paste a command into Terminal. If something feels off, it probably is.

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending

Exit mobile version