This macOS Malware Kills Every App on Your Screen Every 210 Milliseconds Until You Type Your Password. It's Called ClickLock, and It Works Because You'll Do Anything to Make It Stop.
- Patrick Duggan
- 4 hours ago
- 4 min read
Most malware wants to stay invisible. ClickLock does the opposite. It makes itself the only thing you can see, and it makes your Mac unusable on purpose, because a person who cannot open a single application will type their password into almost anything that promises to give their computer back.
The technique is coercion, not stealth
Here is what ClickLock actually does once it's running on a Mac. It kills every visible application, at intervals of roughly 210 milliseconds — about five times a second — so that anything you try to open dies before it finishes drawing. Your browser closes. Your terminal closes. Your settings close. The only window that stays is a fake password dialog the malware controls. There is no menu to reach, no app to launch, no way to work. The machine is functionally a brick with a single prompt on it, and the prompt says it needs your password.
That is not a technical exploit. It is a hostage situation staged on your own desktop, and it is engineered around a simple truth about people: faced with a computer that has stopped working and one box that claims to fix it, most users will type the password. Not because they're careless — because the malware has removed every other option. The genius, if you can call it that, is that it doesn't need to steal your password. It arranges the situation so you hand it over.
How it gets in — and why "just paste this to verify" should terrify you
The entry point is ClickFix, the social-engineering pattern that has quietly become one of the most effective delivery methods of the year. The victim hits a page showing a fake Cloudflare "human verification" sequence — the animated progress bar, the reassuring checkmark aesthetic everyone now trusts — and is instructed to paste a command into their Terminal to "complete verification." They paste it. That command is the infection.
Sit with how good that lure is. It weaponizes a security ritual. We have trained an entire population to see a Cloudflare challenge as the safe part of the internet, the gate that keeps bots out. ClickFix wears that costume and asks you to run a command as the price of admission, and because the costume is trusted, people do. Once run, ClickLock goes after everything worth taking on a Mac: cryptocurrency wallets, saved logins, password-manager data, browser contents, and the macOS authentication data itself — and it can drop a persistent backdoor for return trips.
The infrastructure is built to survive takedown
ClickLock's command-and-control is the part defenders should study, because it is deliberately hard to fight. There is no attacker-owned C2 server to seize. Everything the malware steals leaves through the Telegram Bot API — three Telegram bots, riding Telegram's own encrypted, trusted, un-blockable transport. You cannot null-route Telegram out of a corporate network without breaking a tool half your staff use, and that is exactly the point.
The payloads themselves sit on three compromised domains with clean reputations, one of them a hacked WordPress site. That matters for how you respond, and it's a line we hold: those hosts are victims too. The malware is abusing legitimate sites with earned reputation to slip past domain filters — so the answer is not to blanket-block the domains and punish their owners, it's to recognize the pattern. Malware served from a clean, real site through a Telegram exfil channel is designed specifically to give a blocklist nothing to bite. This is the same shape we keep flagging: the modern operation borrows trusted infrastructure rather than building its own, precisely so there's nothing to take down.
Group-IB, which named and analyzed the stealer, found it had been uploaded to VirusTotal on June 9 with zero detections, and the campaign has already hit at least 100 victims across 33 countries, more than half in Europe, running since roughly May. It is Telegram-controlled, modular, and quiet on the wire — the loud part is only ever pointed at the victim.
What to actually do
The defense against ClickLock is not a signature, because the malware's whole design is to be un-signaturable at the network layer and psychologically overwhelming at the screen. The defense is the thing that happens before the paste.
Teach one rule, and teach it hard: a real human-verification check never asks you to open Terminal and run a command. Cloudflare doesn't. No legitimate website does. The instant a "verification" step tells you to paste anything into a shell, that is the attack, full stop — close the page. This is the single highest-leverage security lesson of 2026 because ClickFix is now delivering a growing share of both Mac and Windows malware, and it defeats every downstream control by getting the user to run the code themselves.
And if a Mac ever traps you — every app dying, one password box that won't leave — do not type the password. That behavior is not a system error; no macOS malfunction kills your apps five times a second and then asks you to authenticate. Force the machine off, and treat it as compromised: the coercion screen is the tell, and the password is what it's there to take.
We hold this at 95 percent, as always — the malware analysis, the victim count, and the infrastructure detail are Group-IB's research, corroborated by the trade press, not our own capture. There are no clean indicators for us to hand you here, and that absence is itself the story: the C2 is Telegram and the payload hosts are hijacked legitimate sites, both chosen so a feed has nothing to enforce. ClickLock cannot be blocked at the wire. It can only be refused at the keyboard — which means the person is the last line, and the lesson is the product.
Sources: Group-IB, "ClickLock Stealer" analysis (July 2026), via Group-IB and BleepingComputer; ClickFix delivery context via RH-ISAC. ClickLock exfiltrates over the Telegram Bot API and stages payloads on compromised legitimate hosts; no attacker-owned blockable infrastructure was published, and we do not blocklist compromised victim domains.
Every indicator in this post is in the feed. Free.
1.58M+ IOCs, STIX 2.1 / TAXII, 88% novel vs ThreatFox, exploited-CVE leads ahead of CISA. No credit card — a free API key in 30 seconds, and you can audit every claim above against the live endpoints.




Comments