A new malware called ClickLock Stealer locks the Mac and closes all applications every 210 ms until the user enters the system password, at which point it captures it and sends it to the attackers. It has been detected since May on at least 100 machines from more than 30 Countries, with more than half of the cases in Europe.
The attack begins with social engineering: the victim is tricked into copying and executing a command in Terminal (For example, a fake Cloudflare human verification), which downloads and installs the malware without the user noticing. Once inside, ClickLock shows a password window that looks legitimate, with the real username and the Apple brand, and if it is canceled, The malware installs itself persistently and starts closing all visible applications (Finder, browser, Terminal, Activity Monitor), leaving only the password window on screen.
When the victim enters the correct password, the malware validates it, sends it to a Telegram bot and proceeds to steal data from browsers, password managers, cryptocurrency wallets, Keychain and FTP credentials; In addition, it installs a backdoor to maintain remote access even after removing other components. The main defense is to never copy or execute Terminal commands from web pages, regardless of their appearance, and to keep the system and security software up to date.
Fountain: Bleeping Computer