Close Menu
The Financial News 247The Financial News 247
  • Home
  • News
  • Business
  • Finance
  • Companies
  • Investing
  • Markets
  • Lifestyle
  • Tech
  • More
    • Opinion
    • Climate
    • Web Stories
    • Spotlight
    • Press Release
What's On

‘A mess of Apple’s own making’

September 1, 2026

Wall Street banks tell Big Law to cut fees as AI speeds up legal work

September 1, 2026

Dow falls 450 points while rising oil prices send Treasury yields racing toward 5%, Iran fears renewed

September 1, 2026

Classic Bay Area deli is closing after 45 years in Menlo Park

September 1, 2026

2 SoCal spots ranked among the best new restaurants of 2026

September 1, 2026
Facebook X (Twitter) Instagram
The Financial News 247The Financial News 247
Demo
  • Home
  • News
  • Business
  • Finance
  • Companies
  • Investing
  • Markets
  • Lifestyle
  • Tech
  • More
    • Opinion
    • Climate
    • Web Stories
    • Spotlight
    • Press Release
The Financial News 247The Financial News 247
Home » New Mac Attack Triggers 83-Hour Password Entry Loop

New Mac Attack Triggers 83-Hour Password Entry Loop

By News RoomJuly 19, 2026No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn WhatsApp Telegram Reddit Email Tumblr
New Mac Attack Triggers 83-Hour Password Entry Loop
Share
Facebook Twitter LinkedIn Pinterest Email

Hot on the heels of reports that password-stealing malware known as CrashStealer was actively targeting macOS users comes yet more bad security news for fans of the Apple ecosystem. Not only does the newly reported ClickLock attack terminate running applications and security tools alike, but it also displays a malicious macOS password prompt that requires the correct system password, which will be extracted by the attackers, or it enters a password-only dialogue loop that lasts for 300,000 seconds. That’s 83 hours of only seeing a password entry screen on your Mac, even if you reboot. Or three and a half days if you prefer. The password-stealing pain only stops if the correct credentials are entered, with the attackers seemingly using this method in an attempt to wear down the victim.

Mac Users Warned To Watch What They Type And Not Enter System Password

That the user is the weakest link is something of a tired, overused security cliché, in my never-humble opinion, but in the case of ClickLock, it’s fairly accurate. At first glance, this looks like just another social engineering attack, employing the now-familiar ClickFix variant that tricks a user into cut-and-pasting commands into the macOS Terminal courtesy of a fake Cloudflare CAPTCHA verification prompt. Unlike previous such threats, ClickLock adopts something akin to a ransomware or extortion threat model to achieve its ultimate credential-stealing goal. Rather than demand a cryptocurrency payment, however, this attack uses a dialogue-fatigue model that makes the system unusable, grounding the victim’s gears until, the attacker hopes, they submit and enter a valid password in the login prompts that is all that is displayed for days on end, even surviving system reboots.

According to a newly published Group-IB threat intelligence report, the ClickLock stealer script was first observed on June 9, targeting “data from 8 browsers, 31 crypto wallet browser extensions, 7 password manager extensions, 8 desktop wallet applications,” and extracting “blockchain addresses across 6 chains, macOS Keychain, shell history and FTP credentials.” Despite the malware still being under active development, based upon an analysis of code structure and assorted artifacts, the researchers have noted attacks across 33 countries so far, and confirmed at least 100 victims.

As much as I hate to admit it, the attackers’ technique is actually very clever indeed. By very effectively making the target system unstable, with functionality impaired to the point that the computer is unusable, the victim is far more likely to enter their password when apparently legitimate login prompts are presented. Especially as the longer the attack continues, the more stressed that victim will become and so more at risk of complying with the malicious requests.

The mitigation is simple, and the Group-IB researchers have essentially said exactly the same as I have repeated time and time again: “Never paste commands into Terminal from websites, regardless of how the page looks or what it claims to verify.” Remember, no legitimate service requires this, whether that’s on a Windows or Mac!

App Killer clickfix attack ClickLock CrashStealer fake password login Mac malware macos password Password Entry Loop
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related News

​The Agentic Web Needs A Trust Layer

September 1, 2026

The GENIUS Act And CLARITY Act Are Infrastructure Opportunities For Banks

September 1, 2026

How Agentic AI Is Coming For The Seat, Not The System

September 1, 2026

Broad AI Adoption Built Fluency, Agents Demand Focus

September 1, 2026

Why Converging Technologies Are Redefining The Role Of The Systems Integrator

September 1, 2026

Controlling Optical Signals For Dynamic Datacenter Switching

September 1, 2026
Add A Comment
Leave A Reply Cancel Reply

Don't Miss

Wall Street banks tell Big Law to cut fees as AI speeds up legal work

Business September 1, 2026

Three of Wall Street’s biggest banks are demanding lower fees from elite attorneys — arguing…

Dow falls 450 points while rising oil prices send Treasury yields racing toward 5%, Iran fears renewed

September 1, 2026

Classic Bay Area deli is closing after 45 years in Menlo Park

September 1, 2026

2 SoCal spots ranked among the best new restaurants of 2026

September 1, 2026
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Our Picks

General Atlantic signs 625 Madison Ave. lease, getting long-awaited project off the ground

September 1, 2026

Who is Alejandro Betancourt, the controversial man behind Trump’s Venezuela oil deal?

September 1, 2026

Alex Spiro repping Josh Kushner’s Thrive in legal fight over $20B FIFA deal

September 1, 2026

​The Agentic Web Needs A Trust Layer

September 1, 2026
The Financial News 247
Facebook X (Twitter) Instagram Pinterest
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact us
© 2026 The Financial 247. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.