Vulnerabilities · 60 days ago
ClickLock turns a fake password prompt into the trust anchor. It does not need to steal a password by guessing. It makes the Mac painful enough to use that some victims will type a valid one, and that one entry unlocks browser sessions, Chrome’s decryption key, Keychain data, and wallet storage in the same run.
Group-IB says the campaign has hit at least 100 victims in 33 countries since May. The malware kills Finder, browsers, Terminal, Activity Monitor, and other apps in tight loops until the user enters a password that it validates locally, so only a real password reaches the operator. It also targets Chrome credentials and cookies, MetaMask, Phantom, FileZilla, and other wallet and account data.
The forward risk is bigger than one cleaned Mac. Any environment that relies on browser-saved passwords, sync tokens, or wallet extensions can lose reusable access material when a user is coerced into one successful prompt.
3 sources covering this story
New ClickLock macOS malware traps users into revealing login password
A new macOS information-stealing malware dubbed ClickLock terminates all visible processes to force users into entering their system login password.
New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password
ClickLock Stealer kills macOS apps every 210 milliseconds until victims enter a password, then steals browser credentials, cookies, wallets, and Keych
Modular macOS Stealer Uses Kill Loops to Force Password Entry
New ClickLock macOS stealer locked victims out of their own system until they surrendered a password
Part of the PlainSec briefing for 2026-07-17