A newly reported macOS threat called ClickLock Stealer uses an unusually aggressive tactic to pressure victims into giving up their login password. According to the report, the malware repeatedly shuts down applications in rapid succession, roughly every 210 milliseconds, creating a disruption that continues until the user enters the requested password.
The infection chain appears to begin with a command that the victim is persuaded to paste into Terminal. After that step, the malware prompts for a password and, if the user refuses or hesitates, it responds by killing open apps in a tight loop. The behavior turns the password prompt into a coercive mechanism rather than a standard-looking security request.
Once a password is entered, ClickLock is described as shifting into data theft. The malware is said to target browser usernames and passwords, cookies, cryptocurrency wallet information, and Keychain-related data, potentially giving attackers access to both online accounts and locally stored secrets.
The case highlights how macOS-focused threats are evolving beyond simple credential prompts into more disruptive social engineering attacks. By combining Terminal-based execution with relentless app termination, ClickLock appears designed to wear down victims until they comply, making it a notable example of pressure-driven infostealer activity on Apple systems.