Daily Security Intel

Archives
Log in
Subscribe
July 17, 2026

[SecurityIntel] 17 Jul | ClickLock macOS Malware Kills Apps For Passwords

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Friday, July 17, 2026

INTEL CONFIDENCE  100%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

ClickLock macOS Malware Kills Apps For Passwords

CRITICAL

5

C2 IPs

49

OTX IOCs

37

ARTICLES

■ ANALYST TLDR

Today's threat landscape is highlighted by the emergence of ClickLock, an aggressive macOS infostealer that forces credential disclosure by repeatedly terminating user processes, alongside modular threats like TELEPUZ and ACR Stealer spreading via ClickFix social engineering lures. Additionally, critical authentication bypass flaws in n8n Enterprise and newly discovered AI data injection techniques highlight growing risks to automated workflows and AI agents. Meanwhile, state-sponsored activity remains high with Sandworm deploying PowerShell-based CAPTCHA tricks and China-linked actors resurfacing with the Daxin and Stupig backdoors.

■ CRITICAL STORIES

CRITICAL#1

New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password

This highly aggressive infostealer bypasses traditional macOS security by terminating visible processes on a tight loop, effectively holding the user's system hostage until they input their login credentials into a fake system dialog.

HIGH#2

n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer

Enterprise instances of the n8n workflow automation platform configured with multiple token issuers are vulnerable to complete account takeover because the platform improperly matches JWTs using only the 'sub' claim while ignoring the 'iss' claim.

HIGH#3

Daxin Resurfaces in Taiwan Alongside Stupig Pre-Login SYSTEM Backdoor

A highly advanced, kernel-mode backdoor linked to Chinese state-sponsored actors has resurfaced in Taiwan's manufacturing sector after four years of silence, accompanied by a new, previously undocumented pre-login SYSTEM backdoor named Stupig.

CRITICAL#4

Coca-Cola says Fairlife ransomware attack halts US dairy production

A ransomware attack targeting Coca-Cola's Fairlife subsidiary has forced a temporary suspension of dairy production across the United States, illustrating the severe real-world operational impacts of cyberattacks on critical manufacturing and OT environments.

■ CVEs IDENTIFIED

[CVE-TBD]

n8n Enterprise — Authentication bypass via JWT validation flaw (ignores 'iss' claim)

Critical

[CVE-TBD]

Splunk — Privilege escalation and credential access

Critical

[CVE-TBD]

Zoom — Account takeover and privilege escalation

Critical

[CVE-TBD]

F5 NGINX / BIG-IP — Remote code execution, memory leak, and configuration modification

Critical

■ THREAT ACTORS

Scattered Spider

Cybercrime Group

Two members (Owen Flowers and Thalha Jubair) sentenced to 5.5 years in the UK for the 2024 Transport for London hack.

Sandworm

State-Sponsored

Targeting Ukrainian users with fake CAPTCHA prompts that trick victims into executing malicious PowerShell commands.

China-linked Threat Actor

State-Sponsored

Deployed the Daxin kernel-mode backdoor ("srt64.sys") and the new Stupig backdoor within a Taiwan manufacturing firm.

■ ATT&CK TTPs

T1566.002
Phishing: Spearphishing Link | ClickFix lures used to deliver ACR Stealer and TELEPUZ malware.
T1204.002
User Execution: Malicious File | Sandworm's fake CAPTCHA trick requiring users to copy/paste PowerShell commands.
T1059.001
Command and Scripting Interpreter: PowerShell | Sandworm executing malicious PowerShell commands.
T1489
Service Stop | ClickLock terminating macOS visible processes every 210ms to force password entry.
T1056.002
Input Capture: GUI Input Capture | ClickLock displaying fake system password prompt.
T1014
Rootkit | Daxin kernel-mode driver backdoor (srt64.sys) used for stealth persistence.

■ PATCH PRIORITY

[P3 PATCH NOW]≤1 week

CRITICAL | n8n Enterprise — JWT authentication bypass allowing unauthorized logins — [THN]

[P3 PATCH NOW]≤1 week

CRITICAL | Splunk — Privilege escalation and credential access vulnerabilities — [SW]

[P3 PATCH NOW]≤1 week

CRITICAL | Zoom — Account takeover and privilege escalation vulnerabilities — [SW]

[P3 PATCH NOW]≤1 week

CRITICAL | F5 NGINX & BIG-IP — Remote code execution and memory leak bugs — [SW]

■ RECOMMENDED ACTIONS TODAY

1[P1] Patch n8n Enterprise instances immediately to resolve the JWT token exchange authentication bypass vulnerability [CVE-TBD].
2[P1] Apply critical security updates for Splunk and Zoom to prevent privilege escalation and account takeover [CVE-TBD].
3[P1] Apply security updates for F5 NGINX and BIG-IP to mitigate remote code execution and memory leak vulnerabilities [CVE-TBD].
4[P2] Deploy detection rules for macOS to identify rapid process termination loops and unauthorized Terminal executions associated with ClickLock Stealer.
5[P2] Restrict permissions and implement strict tool-binding controls for the Anthropic Claude Chrome Extension to prevent unauthorized click-simulation attacks [CVE-TBD].
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
← Newer [SecurityIntel] 18 Jul | Unauthenticated WordPress Core wp2shell RCE Threatens Millions Older → [SecurityIntel] 16 Jul | AsyncAPI npm Supply Chain Compromise Distributes Malware
Powered by Buttondown, the easiest way to start and grow your newsletter.