CrashStealer Malware Impersonates Apple Tool to Steal Mac Passwords and Crypto
A new macOS malware known as ClickLock and CrashStealer impersonates Apple tools to steal passwords and cryptocurrency from users.
🌍 Cross-language spread
This story first appeared in 🇩🇪 German coverage — 26.5 hours before PULSE detected it in English news.
Detected by matching proper nouns and figures that survive translation. Times reflect when each edition's coverage was first indexed.
Velocity
How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →
The brief
A new stealthy stealer malware targeting macOS users has been identified, operating under the names ClickLock and CrashStealer. According to reports from MacRumors and ZDNET, the malware masquerades as an official Apple crash reporter tool to deceive victims. The primary method of infection involves social engineering, where users are prompted to copy and paste a specific text string into their macOS Terminal, as detailed by The Register. Once the system is compromised, the malware focuses on stealing sensitive data, specifically targeting user passwords and cryptocurrency assets. Coverage from The Hacker News and Group-IB emphasizes the aggressive and unique behavior of the ClickLock stealer. The malware employs a tactic where it kills active applications every 210 milliseconds.
This disruptive cycle continues relentlessly until the victim types their password, creating a sense of urgency or system instability to force the user into providing credentials. Cybernews notes that this specific stealer is particularly stealthy because it requires no exploits to function, relying instead on user action to gain a foothold in the system. This threat is significant because it bypasses traditional exploit-based detection by utilizing the Terminal, a powerful system tool. By impersonating a legitimate Apple utility, the malware leverages user trust in the operating system's native crash reporting mechanisms. Group-IB describes the risk in stark terms, suggesting that a single act of pasting the malicious string can lead to a total loss of assets. This highlights a shift toward social engineering where the user is tricked into granting the malware permissions that would otherwise be blocked by macOS security layers.
Looking forward, users are advised to be cautious of instructions requiring the use of the Terminal for unexpected system fixes. ZDNET has highlighted three specific ways to dodge the threat, though the exact technical steps are contained within their full reporting. Security analysts will likely monitor for variations of the ClickLock and CrashStealer code as it attempts to evade detection. Future updates will depend on whether new delivery vectors are identified beyond the current text-string pasting method documented by the reporting outlets.
Synthesized by PULSE from the headlines below under a strict no-invention contract. ✓ fact-checked: all claims supported by sources Updated 7h ago.
Quick answers
How does the ClickLock malware behave once installed?
According to The Hacker News, it kills applications every 210ms until the victim types their password.
How is the malware delivered to the victim?
The Register reports that users are prompted to copy and paste a text string into the macOS Terminal.
What specific data is the malware designed to steal?
MacRumors states that the malware is designed to steal Mac passwords and cryptocurrency.
Coverage (6)
- C'mon, just copy this text string and paste it into your macOS Terminal The Register · 11d ago
- ClickLock Stealer: Paste Once, Lose Everything Group-IB · 11d ago
- MacOS users, beware: newly discovered stealthy stealer requires no exploits Cybernews · 11d ago
- New Mac malware masquerades as Apple's crash reporter: 3 ways to dodge the threat ZDNET · 11d ago
- New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password The Hacker News · 11d ago
- CrashStealer Malware Impersonates Apple Tool to Steal Mac Passwords and Crypto MacRumors · 11d ago
Topics
Related trends
Apple Planning to Unveil Privacy-Focused Smart Glasses at WWDC 2027
Apple is reportedly preparing to unveil privacy-focused smart glasses at WWDC 2027 following significant development delays.
What to Expect From Apple Watch Series 12 and Apple Watch Ultra 4
Anticipation builds for the Apple Watch Series 12 and Ultra 4 as leaks suggest major battery and chip upgrades despite a lack of design changes.
Apple’s Smart Glasses Will Need to Overcome Meta’s Privacy Reputation
Apple is preparing to enter the smart glasses market, aiming to leverage privacy protections to differentiate itself from Meta's existing reputation.
ClickLock Mac malware locks apps until you give in
New ClickLock and ClickFix malware target Mac users, employing extortion and data theft to compromise crypto wallets and enterprise fleets.
Downloaded a custom map for Meccha Chameleon recently? A researcher says it may have installed malware on your PC.
Users of the indie hit Meccha Chameleon are warned of malware spreading via custom Steam Workshop maps and a breached official Discord server.
The Downsides Of Switching From Android To iPhone
Coverage examines shifting device ecosystems as CIRP data highlights consumer choices when moving from Android to iPhone.