New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password

A highly aggressive macOS malware, dubbed ClickLock, is wreaking havoc on Apple users worldwide, forcing them to constantly re-enter their password credentials every 210 milliseconds until they comply. This ruthless stealer app has been quietly spreading its tentacles across various countries, targeting individuals and organizations alike.

ClickLock’s modus operandi revolves around exploiting a critical vulnerability in macOS’s built-in software update mechanism. The malware cleverly inserts itself into the system by masquerading as an authentic Apple update prompt. When a user falls for this ruse, ClickLock begins its nefarious activities: it swiftly scans the infected device for sensitive data, steals login credentials, and disables all running applications – essentially holding the victim’s digital life hostage.

The malware’s primary objective is to extort victims into surrendering their password information by repeatedly crashing their apps. As long as the apps remain disabled, ClickLock continues to bombard the user with error messages demanding that they re-enter their credentials every 210 milliseconds. This relentless barrage wears down even the most vigilant users, creating an ideal opportunity for the malware to infiltrate deeper into the system and pilfer valuable data.

The sheer speed and ferocity of ClickLock’s attacks make it a formidable foe in the world of cybersecurity. As AI-powered threat detection tools become increasingly sophisticated, they are now being leveraged by malicious actors to develop highly effective exploit kits – underscoring the need for organizations to invest in robust security measures that can keep pace with these evolving threats.

ClickLock’s success is also a stark reminder of the importance of user education and awareness. In today’s digital landscape, where cybersecurity threats are becoming increasingly sophisticated, individuals must be vigilant about verifying the authenticity of software updates and other online prompts. Furthermore, organizations should prioritize implementing robust security protocols that encompass AI-driven threat detection and response capabilities.

In light of this recent development, it is essential for users to exercise extreme caution when interacting with their devices. Always verify the source of any software update or prompt before proceeding, and ensure that your organization’s cybersecurity infrastructure is equipped to handle the evolving threat landscape. By staying one step ahead of these malicious actors, we can collectively fortify our defenses against the increasingly complex world of cyber threats.


Source: The Hacker News — 2026-07-16