Skip to content

MacSync

MacSync Stealer is a macOS-focused infostealer used in socially engineered infection chains that rely on users executing attacker-supplied Terminal commands, most notably through ClickFix-style lures.

Profile source: Mallory opens in a new tab

MacSync

Family profile

MacSync Stealer is a macOS-focused infostealer used in socially engineered infection chains that rely on users executing attacker-supplied Terminal commands, most notably through ClickFix-style lures. Observed campaigns have used counterfeit software-installation guidance, fake GitHub-themed pages, and malvertising-driven prompts that instruct victims to paste a curl command into zsh or Terminal, after which native macOS tools and AppleScript-assisted execution retrieve, unpack, and launch the payload.

The malware is designed to collect high-value data from compromised Mac systems. Reported collection targets include macOS Keychain material, browser credentials, cookies, session data, IndexedDB and LevelDB content, browser profile artifacts, Safari data, Apple Notes, Telegram sessions, SSH keys, cloud and developer secrets such as AWS credentials and Kubernetes configurations, and sensitive user documents. It also targets cryptocurrency-related data, including wallet artifacts, hardware-wallet companion data, and in some reporting, wallet recovery phrases through tampering with wallet applications.

MacSync Stealer stages harvested data in temporary locations, compresses it into an archive, splits the archive into chunks, and exfiltrates the results over HTTP PUT using curl. It has also been observed deleting temporary staging material and other artifacts after upload. Some reporting further describes a broader multi-component intrusion set associated with MacSync that includes persistence via a LaunchAgent, a remote-access component capable of interactive shell access and file transfer, screen-capture functionality after user consent, and modification of cryptocurrency wallet applications to phish for seed phrases.

The malware has been tracked through durable behavioral patterns rather than static infrastructure because its operators rotate delivery and command infrastructure rapidly. MacSync Stealer has been discussed alongside other macOS stealers such as Atomic Stealer (AMOS), CrashStealer, and AmnesiaStealer due to overlapping objectives and shared lure templates, but available reporting does not conclusively attribute it to a named threat actor. It primarily targets macOS users and is relevant to environments where browser-stored credentials, developer secrets, cloud access material, and cryptocurrency assets are present.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Persistence
  • Post Exploitation
  • Session Hijacking

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 22, 2026
Last activity
Aug 22, 2026
Feed role
C2 / Distribution
Host form
0 IP / 3 hostnames

Leading locations

  • US2
  • AU1

Leading providers

  • Cloudflare, Inc.2
  • Akamai Connected Cloud1

Infrastructure traits

  • Hosting 3
  • Anycast 2

Samples

Recent associated samples

Exploited software

Vulnerabilities linked to MacSync

1 CVEs

MITRE ATT&CK

MacSync in ATT&CK

80 distinct techniques

Techniques

80 techniques
T1140 Deobfuscate/Decode Files or Information T1020 Automated Exfiltration T1518 Software Discovery T1070.004 File Deletion T1071.001 Web Protocols T1030 Data Transfer Size Limits T1082 System Information Discovery T1059.004 Unix Shell T1555.001 Keychain T1560.001 Archive via Utility T1105 Ingress Tool Transfer T1555.003 Credentials from Web Browsers T1552.001 Credentials In Files T1041 Exfiltration Over C2 Channel T1005 Data from Local System T1057 Process Discovery T1528 Steal Application Access Token T1567 Exfiltration Over Web Service T1113 Screen Capture T1543.001 Launch Agent T1083 File and Directory Discovery T1027 Obfuscated Files or Information T1070 Indicator Removal T1074 Data Staged T1649 Steal or Forge Authentication Certificates T1555 Credentials from Password Stores T1204 User Execution T1583 Acquire Infrastructure T1560 Archive Collected Data T1219 Remote Access Tools T1059.002 AppleScript T1539 Steal Web Session Cookie T1098.004 SSH Authorized Keys T1552.004 Private Keys T1566 Phishing T1552 Unsecured Credentials T1620 Reflective Code Loading T1216.002 SyncAppvPublishingServer T1053 Scheduled Task/Job T1056.001 Keylogging T1598 Phishing for Information T1497.001 System Checks T1497 Virtualization/Sandbox Evasion T1622 Debugger Evasion T1036 Masquerading T1059 Command and Scripting Interpreter T1583.001 Domains T1056 Input Capture T1053.005 Scheduled Task T1548 Abuse Elevation Control Mechanism T1071 Application Layer Protocol T1037.004 RC Scripts T1573.002 Asymmetric Cryptography T1571 Non-Standard Port T1554 Compromise Host Software Binary T1056.002 GUI Input Capture T1553 Subvert Trust Controls T1657 Financial Theft T1074.001 Local Data Staging T1556 Modify Authentication Process T1546 Event Triggered Execution T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol T1218 System Binary Proxy Execution T1566.002 Spearphishing Link T1204.002 Malicious File T1608.006 SEO Poisoning T1656 Impersonation T1543.004 Launch Daemon T1027.002 Software Packing T1548.002 Bypass User Account Control T1008 Fallback Channels T1204.004 Malicious Copy and Paste T1553.002 Code Signing T1195.002 Compromise Software Supply Chain T1048 Exfiltration Over Alternative Protocol T1003 OS Credential Dumping T1090 Proxy T1614 System Location Discovery T1574 Hijack Execution Flow T1562.001 Disable or Modify Tools

Reporting

Research mentioning MacSync

Aug 17
Huntress

MacSync Stealer: How a Google Search for Claude Led to a macOS Infostealer | Huntress

A malvertising campaign used sponsored Google search results for Anthropic's Claude to lure macOS users to a legitimate shared conversation page on claude.ai, where they were socially engineered into running a malicious terminal command. Huntress reported that the command fetched MacSync, a multi-stage macOS infostealer and remote access trojan that chains a zsh loader, in-memory AppleScript theft, a persistent Mach-O RAT, and a helper component designed to abuse Screen Recording permissions. The malware was built to steal a wide range of data from infected Macs, including browser data, Keychain secrets, saved passwords, Telegram sessions, SSH and cloud credentials, and cryptocurrency wallet recovery phrases. The operation also used repeated TCC permission prompts, fake "Apple Support" messaging, and trojanized cryptocurrency wallet applications to deepen access, maintain persistence, and expand theft beyond initial credential harvesting.

Aug 5
The Hacker News

Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures

Microsoft reported that a macOS-focused ClickFix campaign evolved from openly serving fake download pages to using server-side browser fingerprinting that shows the malicious lure mainly to likely macOS victims. The operation used more than 250 look-alike domains, often following dictionary-style naming patterns that included the token file, and presented spoofed GitHub-themed pages with a fake Download for macOS prompt. Victims were tricked into pasting a Terminal command that fetched remote scripts and installed infostealers including Atomic Stealer (AMOS) and MacSync. The gating logic collected browser, hardware, and anti-analysis signals before deciding whether to deliver the lure, including navigator data, WebGL GPU details, timezone, iframe status, touch support, console serialization behavior, and prototype-tamper checks; non-qualifying visitors were sent blank or benign decoy pages. Separate IOC material tied the same broader activity to additional macOS infostealer infrastructure, including SHub Stealer, suspected delivery and command-and-control domains, a SHA-256 sample hash, and capabilities such as screenshot capture, file download, command execution, and self-deletion, reinforcing that the campaign relied on rotating lure domains and stealthy staging to target macOS users.

Aug 5
Microsoft General

From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide | Microsoft Security Blog

Jul 23
Red Canary

Intelligence Insights: July 2026 | Red Canary

Researchers reported continued activity around CastleLoader/CastleBot malware delivery chains alongside a resurgence of KongTuke, with both threats relying heavily on social-engineering lures and staged payload delivery. Red Canary said CastleLoader remained active since early 2025 and was commonly delivered through paste-and-run fake CAPTCHA or impersonation websites, while Trend Micro documented KongTuke abusing compromised WordPress sites in ClickFix-style infection flows. The campaigns reflect a broader shift toward user-assisted execution, where victims are tricked into launching malicious commands that initiate multi-stage malware retrieval. Technical analysis from IBM and Splunk tied the Castle ecosystem to a malware-as-a-service operation and detailed the tooling used after execution, including use of finger.exe to fetch batch commands, portable Python interpreters as a bring-your-own-interpreter technique, multilayer-obfuscated Python loaders, RC4-encrypted payload retrieval, and process injection into python.exe. Splunk's review of Castle RAT highlighted the client malware's tactics and ATT&CK-mapped behavior, while Red Canary noted anti-analysis checks, C2-based tasking, and detection opportunities such as repeated caret obfuscation in cmd.exe command lines. Together, the reporting shows an active loader-and-RAT ecosystem being distributed through fake verification pages and compromised web infrastructure.

Jul 21
Security Online Info

ClickLock Stealer: macOS Malware That Locks You Out

Researchers reported a new macOS infostealer dubbed ClickLock Stealer that tricks users into pasting a malicious bash command into Terminal through ClickFix-style pages masquerading as Cloudflare verification prompts. Group-IB said the malware has been active since at least late May and has targeted at least 100 users in 33 countries, with more than half of victims in Europe. Once launched, the malware downloads multiple payloads for browser credential theft, cryptocurrency wallet theft, Keychain theft, password manager and FileZilla credential collection, shell history harvesting, and backdoor installation, then exfiltrates the stolen data to a Telegram bot. Researchers also linked the campaign to LaunchAgent persistence and a backdoor called goyim derived largely from GSocket tooling. ClickLock does not rely on a software exploit or privilege escalation; instead, it abuses user execution and suppresses defenses by repeatedly killing visible applications and NotificationCenter, sometimes every 210 milliseconds, until victims enter their macOS password and approve Keychain access. Apple separately published guidance warning that scammers increasingly use websites, chat agents, messaging platforms, and email to socially engineer Mac users into pasting unsafe Terminal commands, and said macOS may warn or block commands and scripts associated with known malware. Apple said such alerts mean the Mac has not yet been harmed and advised users not to run untrusted commands or scripts unless they fully trust the source.

Jul 20
Macrumors

'ClickLock' Malware Coerces Mac Users Into Giving Up Passwords - MacRumors

Jul 20
Xakep

Стилер ClickLock для macOS завершает процессы, вынуждая жертву ввести пароль - Хакер

Jul 18
Cysecurity News

Group-IB Uncovers ClickLock macOS Malware Targeting Passwords and Crypto Wallets - CySecurity News - Latest Information Security and Hacking Incidents

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.