ClickLock Mac Malware Uses Brutal Kill Loop to Force System Passwords

by priyanka.patel tech editor
The Mechanics of the ClickLock Kill Loop

A new macOS infostealer dubbed ClickLock is forcing victims to provide their system passwords by repeatedly killing essential applications in a 210-millisecond loop.

The Mechanics of the ClickLock Kill Loop

ClickLock distinguishes itself from traditional malware through a persistent, disruptive coercion strategy. If a user refuses to provide their system password after being prompted by a fake dialog, the malware initiates a destructive cycle. The process repeats every 210 milliseconds for up to 83 hours, rendering the desktop essentially unusable until the victim complies.

The malware’s design is intentional; it is built to capitalize on the user’s frustration. Securityboulevard reports that the malware displays a convincing fake macOS password prompt, complete with the victim’s real username and a stolen Apple icon. This creates a high-pressure environment where the only interactive element on the screen is the password entry field, designed to force the user into handing over their credentials.

Infection and Distribution via ClickFix

The distribution of ClickLock relies on the “ClickFix” technique, where victims are tricked into executing malicious commands themselves. Users land on phishing pages that masquerade as system utilities or Cloudflare verification flows. These pages instruct the user to open Terminal, paste a specific command, and press Return under the guise of human verification or a system fix.

Once executed, the script disables keyboard interrupts and hides the cursor, while displaying a fake progress bar to distract the victim. The malware then orchestrates a variety of modules to harvest sensitive information. As Securityboulevard noted, the malware orchestrates further modules that search the system for various data including browser credentials, password manager data, crypto wallet extensions, desktop wallet files, etc. and even employs a GSocket backdoor.

Persistent Access and Data Exfiltration

Even after a victim enters their password and the immediate theft is complete, the threat to the system remains. The malware installs LaunchAgents that ensure its persistence. One of these agents continues the kill loop if the password is not provided, while another operates in the background to query the Keychain for Chrome’s Safe Storage key.

The exfiltration process is notably automated. The stolen data is sent to Telegram channels controlled by the attackers. This backdoor allows the attackers to maintain remote access to the compromised machine even after the primary stealer components have self-deleted.

Scope of the Campaign and Defensive Measures

Because the orchestrator script was uploaded to VirusTotal on June 9 with zero detections, the malware initially bypassed security filters.

For those who have already executed the malicious commands, experts recommend a comprehensive security reset. This includes revoking all active browser sessions and treating all saved passwords, cookies, and cryptocurrency wallet keys as compromised.

You may also like