← Back to Tech & Science

New macOS Stealer ClickLock Disables Applications to Force Credential Theft

Tech & ScienceAI-Generated & Algorithmically Scored··1 UPDATE

AI-generated from multiple sources. Verify before acting on this reporting.

Update

Additional reports have emerged confirming the widespread impact of the ClickLock Stealer campaign. These new accounts corroborate earlier findings regarding the malware's aggressive application-termination tactics on macOS systems. The influx of verified incidents strengthens the understanding of the attack's scale and operational reach since its initial deployment in mid-July 2026. Security analysts note that these fresh details align with previous observations, reinforcing the severity of the threat to Apple users globally. No new technical variants have been identified at this time, but the volume of confirmed cases suggests a broader distribution than initially estimated.

Original Report —

A sophisticated new infostealing malware targeting Apple computers has emerged, employing an aggressive tactic of forcibly terminating user applications every 210 milliseconds until victims surrender their login credentials. The threat actor behind the operation, identified as the operator of the ClickLock Stealer, deployed the malicious software globally on July 16, 2026.

The malware functions by systematically crashing active processes on infected macOS systems in a rapid loop designed to render the operating system unusable for standard tasks. This disruption continues indefinitely until the user enters their account password into what appears to be a legitimate login prompt. Once the credential is provided, ClickLock executes its primary payload: harvesting sensitive data stored within web browsers, including saved passwords and session cookies. The tool further targets cryptocurrency wallets and extracts entries from the macOS Keychain, Apple's central repository for encrypted secrets.

Security analysts at Group-IB have documented the spread of the malware across 33 countries, with a significant concentration of attacks observed in Europe. The campaign represents an escalation in tactics against Mac users, who are increasingly becoming targets for financial cybercrime operations previously focused on Windows environments. By combining application denial-of-service mechanisms with credential harvesting, ClickLock bypasses traditional security measures that rely on user behavior or passive monitoring.

The stolen data is typically exfiltrated to command-and-control servers operated by the threat group, where it can be sold on underground markets or used for direct financial fraud and identity theft. The 210-millisecond kill cycle creates a high-pressure environment intended to panic victims into complying with the malware's demands without attempting technical remediation.

While the specific motivation behind this campaign remains unconfirmed, the precision of the code suggests an organized effort rather than opportunistic activity. Cybersecurity experts warn that standard antivirus solutions may struggle to detect ClickLock due to its reliance on legitimate system calls for process termination and data extraction. The rapid global dissemination indicates a mature distribution network capable of reaching diverse geographic regions simultaneously.

Questions remain regarding the origin of the initial infection vectors used to deliver ClickLock onto victim machines, as well as whether other variants with similar mechanics are currently in development. Authorities have not yet identified the individuals or organizations responsible for orchestrating the campaign. As investigations continue, users across Europe and beyond face heightened risks from this new class of ransomware-adjacent threats that prioritize immediate data extraction over system encryption.

Discussion

0 / 2000