Last seven days
- First activity
- Oct 1, 2026
- Last activity
- Oct 1, 2026
- Feed role
- Distribution
- Host form
- 0 IP / 1 hostnames
MacSync is a macOS information-stealing malware family offered under a malware-as-a-service model.
Profile source: Mallory opens in a new tabMacSync
MacSync is a macOS information-stealing malware family offered under a malware-as-a-service model. First advertised in 2025 as Mac.c, it was subsequently renamed MacSync. It targets both Intel-based and Apple Silicon Macs, with campaigns focused on developers, cryptocurrency users, and other IT-associated users. Distribution methods include ClickFix lures, malicious advertisements, cracked software, and fraudulent applications packaged in DMG disk images. Campaigns have impersonated cryptocurrency wallets and used shared AI-platform pages to persuade users to execute malicious Terminal commands. MacSync has also been deployed in PasteSwitch malvertising activity.
An updated variant observed in September 2026 combines a Swift-based infostealer with an Objective-C backdoor and uses multistage binary loaders and droppers. Some infection chains retrieve shell commands concealed in public iCloud Calendar event descriptions and download subsequent application bundles from iCloud infrastructure. Evasion measures include removal of macOS quarantine metadata, encrypted payload delivery, in-memory execution, virtual-machine checks, debugger blocking, and deletion of temporary artifacts and logs. Module delivery uses Curve25519 key exchange and AES-GCM encryption.
MacSync uses fraudulent administrator-password dialogs and validates captured passwords through macOS authentication interfaces. It collects browser histories, cookies, saved credentials, cryptocurrency-wallet application and extension data, Telegram data and sessions, macOS Keychain files, device credentials, and system information. It also targets SSH keys, cloud and developer configurations, Git and Kubernetes data, and shell-command histories, exfiltrating collected information to attacker infrastructure.
The backdoor masquerades as Finder and establishes persistence through LaunchAgents, shell-startup modifications, and global Git hooks. Restoration routines recover deleted components, while termination of macOS notification processes conceals persistence-related alerts. It can execute attacker-supplied AppleScript, collect and upload additional files, deploy browser extensions, and replace installed Ledger wallet software with an attacker-provided version.
Samples
Exploited software
MITRE ATT&CK
Reporting
Attackers abused ChatGPT Custom GPT pages branded as “Plus 5.6” and promoted them through sponsored Google Search results to impersonate a legitimate ChatGPT model. Victims were redirected to a fake backup domain hosting a Google Sites page styled as ChatGPT and Cloudflare verification prompts; the ClickFix lure instructed them to run PowerShell, silently installing a malicious MSI and a sophisticated remote-access trojan (RAT). Huntress handled at least 40 incidents tied to the Google Sites domain, including two confirmed infections originating from Custom GPT lures, and observed replacement lures after the original was removed. The campaign used signed third-party software for DLL sideloading and layered persistence. An initial variant abused Canon-signed CaptureOnTouch components, concealed its loader in a WAV file, and created Run-key and scheduled-task persistence labeled “Canon Configuration Reader.” A second variant preserved the RAT framework but used Stardock-signed DeElevate64.exe, a modified DeElevator64.dll, and a NuGet package carrier, establishing persistence as “Stardock DeElevation Tool.” Organizations should treat sponsored AI-tool search results and browser verification prompts that require shell commands as high-risk social-engineering activity.
A new DarkMe remote-access Trojan campaign has shifted from the exploit-led delivery associated with Water Hydra to straightforward phishing. Lures disguised as image links served executable .PIF files, which launched a remote MSI installer and a multistage Visual Basic 6 loader chain. The chain registers a COM object and invokes it through rundll32.exe /sta {CLSID}, checks for sandbox-like processes, creates persistence through a custom Locked:// URI handler, and process-hollows the signed Microsoft clspack.exe binary. The final payload combines remote-access and infostealing functions: it can collect cryptocurrency-wallet data, take screenshots, enumerate installed antivirus products, manipulate files, and run commands. It communicates over custom TCP command-and-control on port 7712; observed infrastructure included thatawful[.]boutique resolving to 67.43.50[.]11:7712. Organizations should block the identified infrastructure, investigate .PIF downloads and suspicious remote MSI execution, and hunt for the rundll32.exe /sta COM-launch pattern and unauthorized Locked:// registry protocol handlers.
A threat actor impersonated a CoinDesk marketing executive in X direct messages, using post-Black Hat and DEFCON cryptocurrency-conference lures to target security researchers. The messages linked to legitimate Google Docs containing container-bound Google Apps Script that profiled visitors and sent their IP address, geolocation, browser details, and cryptocurrency-wallet-extension data to the operator through Telegram. The campaign routed victims to operating-system-specific malware: macOS users received a variant of the AMOS infostealer, while Windows users were served an encoded PowerShell loader chain and installers signed with three stolen or fraudulently issued certificates. Recovered Windows components included a malicious NetSupport Manager deployment, a persistent rogue local certificate authority capable of TLS interception, and a Ledger-wallet-focused implant. Russian-language comments and C2 artifacts indicate the operator may be Russian-speaking, but no threat group has been attributed.
Attackers compromised the verified Reddit account u/hbomax and used it to run 108 malicious advertisements over roughly 48 hours. The ads impersonated HBO Max, AI-development tools, and macOS utilities, directing targets into a ClickFix campaign researchers call PasteSwitch that persuaded victims to copy and execute commands in a terminal or Windows Run dialog. The copied commands selected payloads by operating system: macOS victims received MacSync and AMOS Helper stealers, while a Windows InstallFix chain loaded Amatera Stealer in memory. The campaign also deployed fake cryptocurrency wallets and crypto clippers, using direct-to-IP TLS communications and Binance Smart Chain smart contracts to rotate clipper command-and-control domains. Reddit paused the malicious ads and began an internal investigation to secure the compromised account.
MacSync, a malware-as-a-service macOS stealer and remote-access stager, is being distributed through ClickFix social engineering, SEO poisoning, malvertising, compromised websites, and fake software or AI installers that prompt victims to run Terminal commands. Its native 64-bit Mach-O stager daemonizes itself, XOR-decrypts its configuration, downloads an AppleScript stealer from command-and-control (C2) infrastructure, and executes it in memory through osascript. The malware targets Keychain records, browser credentials and cookies, SSH keys, messaging sessions, cloud credentials, cryptocurrency wallets, and sensitive files. It archives collected data and exfiltrates it in 10 MB HTTP PUT chunks before deleting local staging artifacts; analyzed samples used drivinguber.com as primary C2 infrastructure and newsinweb.com-derived hosts as fallbacks. Public reporting associates MacSync with the earlier Mac.C Stealer and the developer identity “Mentalpositive,” though Russian-language artifacts do not substantiate attribution to a particular actor, syndicate, or affiliate campaign.