Skip to content

MacSync

MacSync Stealer is a macOS-exclusive information-stealing malware family offered under a malware-as-a-service model.

Profile source: Mallory opens in a new tab

MacSync

Family profile

MacSync Stealer is a macOS-exclusive information-stealing malware family offered under a malware-as-a-service model. It is delivered primarily through ClickFix social engineering, search-engine malvertising, SEO poisoning, compromised websites, and fraudulent software or AI-service installation pages. Lures impersonate well-known software, collaboration, AI, cloud, and cryptocurrency services and persuade victims to paste attacker-supplied commands into Terminal. Public reporting has linked the family to the earlier Mac.C Stealer and a developer identity known as Mentalpositive, although available evidence does not support definitive attribution to a specific threat actor or syndicate.

MacSync uses native macOS tooling and AppleScript-assisted execution to retrieve dynamically supplied payloads, collect data, and communicate with command-and-control infrastructure. Its native stager can detach from the originating Terminal session, obfuscate embedded configuration, execute remotely retrieved AppleScript without saving it as a script file, and suppress console output. The stealer targets macOS Keychain material, saved browser credentials, cookies and other browser-session data, SSH keys, cloud credentials, messaging-session data, Apple Notes, Safari data, Kubernetes configuration, sensitive documents, and cryptocurrency wallet artifacts. It packages stolen information into an archive, uploads it in chunks through HTTP PUT requests, and removes temporary staging material after successful exfiltration.

Observed MacSync chains can deploy a persistent remote-access component through a LaunchAgent, enabling interactive shell access, command execution, and file transfer. Other components request sensitive macOS permissions, including Screen Recording, and can modify cryptocurrency wallet applications or extensions to solicit wallet recovery phrases. Reporting has identified activity affecting users in technology and software organizations, cryptocurrency and Web3 communities, financial services, remote-work environments, and government or defense-related roles.

Capabilities

  • Credential Theft
  • Crypto Theft
  • Defense Evasion
  • Exfiltration
  • Persistence
  • Post Exploitation
  • Reconnaissance
  • Session Hijacking

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 2, 2026
Last activity
Sep 7, 2026
Feed role
C2 / Distribution
Host form
0 IP / 5 hostnames

Leading locations

  • US5

Leading providers

  • Cloudflare, Inc.5

Infrastructure traits

  • Anycast 5
  • Hosting 5

Samples

Recent associated samples

Exploited software

Vulnerabilities linked to MacSync

1 CVEs

MITRE ATT&CK

MacSync in ATT&CK

82 distinct techniques

Techniques

82 techniques
T1204.002 Malicious File T1543.001 Launch Agent T1562.001 Disable or Modify Tools T1082 System Information Discovery T1036.005 Match Legitimate Resource Name or Location T1564.001 Hidden Files and Directories T1027 Obfuscated Files or Information T1071.001 Web Protocols T1070.004 File Deletion T1030 Data Transfer Size Limits T1059.002 AppleScript T1539 Steal Web Session Cookie T1059.004 Unix Shell T1555.001 Keychain T1560.001 Archive via Utility T1552.004 Private Keys T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol T1105 Ingress Tool Transfer T1204.004 Malicious Copy and Paste T1555 Credentials from Password Stores T1566.002 Spearphishing Link T1036 Masquerading T1140 Deobfuscate/Decode Files or Information T1020 Automated Exfiltration T1518 Software Discovery T1555.003 Credentials from Web Browsers T1552.001 Credentials In Files T1041 Exfiltration Over C2 Channel T1005 Data from Local System T1057 Process Discovery T1528 Steal Application Access Token T1567 Exfiltration Over Web Service T1113 Screen Capture T1083 File and Directory Discovery T1070 Indicator Removal T1074 Data Staged T1649 Steal or Forge Authentication Certificates T1204 User Execution T1583 Acquire Infrastructure T1560 Archive Collected Data T1219 Remote Access Tools T1098.004 SSH Authorized Keys T1566 Phishing T1552 Unsecured Credentials T1620 Reflective Code Loading T1216.002 SyncAppvPublishingServer T1053 Scheduled Task/Job T1056.001 Keylogging T1598 Phishing for Information T1497.001 System Checks T1497 Virtualization/Sandbox Evasion T1622 Debugger Evasion T1059 Command and Scripting Interpreter T1583.001 Domains T1056 Input Capture T1053.005 Scheduled Task T1548 Abuse Elevation Control Mechanism T1071 Application Layer Protocol T1037.004 RC Scripts T1573.002 Asymmetric Cryptography T1571 Non-Standard Port T1554 Compromise Host Software Binary T1056.002 GUI Input Capture T1553 Subvert Trust Controls T1657 Financial Theft T1074.001 Local Data Staging T1556 Modify Authentication Process T1546 Event Triggered Execution T1218 System Binary Proxy Execution T1608.006 SEO Poisoning T1656 Impersonation T1543.004 Launch Daemon T1027.002 Software Packing T1548.002 Bypass User Account Control T1008 Fallback Channels T1553.002 Code Signing T1195.002 Compromise Software Supply Chain T1048 Exfiltration Over Alternative Protocol T1003 OS Credential Dumping T1090 Proxy T1614 System Location Discovery T1574 Hijack Execution Flow

Reporting

Research mentioning MacSync

Sep 8
Malware News

MacSync: The Evasive macOS Stealer Exploiting ClickFix Lures - Malware News - Malware Analysis, News and Indicators

MacSync, a malware-as-a-service macOS stealer and remote-access stager, is being distributed through ClickFix social engineering, SEO poisoning, malvertising, compromised websites, and fake software or AI installers that prompt victims to run Terminal commands. Its native 64-bit Mach-O stager daemonizes itself, XOR-decrypts its configuration, downloads an AppleScript stealer from command-and-control (C2) infrastructure, and executes it in memory through osascript. The malware targets Keychain records, browser credentials and cookies, SSH keys, messaging sessions, cloud credentials, cryptocurrency wallets, and sensitive files. It archives collected data and exfiltrates it in 10 MB HTTP PUT chunks before deleting local staging artifacts; analyzed samples used drivinguber.com as primary C2 infrastructure and newsinweb.com-derived hosts as fallbacks. Public reporting associates MacSync with the earlier Mac.C Stealer and the developer identity “Mentalpositive,” though Russian-language artifacts do not substantiate attribution to a particular actor, syndicate, or affiliate campaign.

Sep 8
Seqrite

MacSync: The Evasive macOS Stealer Exploiting ClickFix Lures | Seqrite

Aug 17
Huntress

MacSync Stealer: How a Google Search for Claude Led to a macOS Infostealer | Huntress

A malvertising campaign used sponsored Google search results for Anthropic's Claude to lure macOS users to a legitimate shared conversation page on claude.ai, where they were socially engineered into running a malicious terminal command. Huntress reported that the command fetched MacSync, a multi-stage macOS infostealer and remote access trojan that chains a zsh loader, in-memory AppleScript theft, a persistent Mach-O RAT, and a helper component designed to abuse Screen Recording permissions. The malware was built to steal a wide range of data from infected Macs, including browser data, Keychain secrets, saved passwords, Telegram sessions, SSH and cloud credentials, and cryptocurrency wallet recovery phrases. The operation also used repeated TCC permission prompts, fake "Apple Support" messaging, and trojanized cryptocurrency wallet applications to deepen access, maintain persistence, and expand theft beyond initial credential harvesting.

Aug 5
The Hacker News

Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures

Microsoft reported that a macOS-focused ClickFix campaign evolved from openly serving fake download pages to using server-side browser fingerprinting that shows the malicious lure mainly to likely macOS victims. The operation used more than 250 look-alike domains, often following dictionary-style naming patterns that included the token file, and presented spoofed GitHub-themed pages with a fake Download for macOS prompt. Victims were tricked into pasting a Terminal command that fetched remote scripts and installed infostealers including Atomic Stealer (AMOS) and MacSync. The gating logic collected browser, hardware, and anti-analysis signals before deciding whether to deliver the lure, including navigator data, WebGL GPU details, timezone, iframe status, touch support, console serialization behavior, and prototype-tamper checks; non-qualifying visitors were sent blank or benign decoy pages. Separate IOC material tied the same broader activity to additional macOS infostealer infrastructure, including SHub Stealer, suspected delivery and command-and-control domains, a SHA-256 sample hash, and capabilities such as screenshot capture, file download, command execution, and self-deletion, reinforcing that the campaign relied on rotating lure domains and stealthy staging to target macOS users.

Aug 5
Microsoft General

From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide | Microsoft Security Blog

Jul 23
Red Canary

Intelligence Insights: July 2026 | Red Canary

Researchers reported continued activity around CastleLoader/CastleBot malware delivery chains alongside a resurgence of KongTuke, with both threats relying heavily on social-engineering lures and staged payload delivery. Red Canary said CastleLoader remained active since early 2025 and was commonly delivered through paste-and-run fake CAPTCHA or impersonation websites, while Trend Micro documented KongTuke abusing compromised WordPress sites in ClickFix-style infection flows. The campaigns reflect a broader shift toward user-assisted execution, where victims are tricked into launching malicious commands that initiate multi-stage malware retrieval. Technical analysis from IBM and Splunk tied the Castle ecosystem to a malware-as-a-service operation and detailed the tooling used after execution, including use of finger.exe to fetch batch commands, portable Python interpreters as a bring-your-own-interpreter technique, multilayer-obfuscated Python loaders, RC4-encrypted payload retrieval, and process injection into python.exe. Splunk's review of Castle RAT highlighted the client malware's tactics and ATT&CK-mapped behavior, while Red Canary noted anti-analysis checks, C2-based tasking, and detection opportunities such as repeated caret obfuscation in cmd.exe command lines. Together, the reporting shows an active loader-and-RAT ecosystem being distributed through fake verification pages and compromised web infrastructure.

Jul 21
Security Online Info

ClickLock Stealer: macOS Malware That Locks You Out

Researchers reported a new macOS infostealer dubbed ClickLock Stealer that tricks users into pasting a malicious bash command into Terminal through ClickFix-style pages masquerading as Cloudflare verification prompts. Group-IB said the malware has been active since at least late May and has targeted at least 100 users in 33 countries, with more than half of victims in Europe. Once launched, the malware downloads multiple payloads for browser credential theft, cryptocurrency wallet theft, Keychain theft, password manager and FileZilla credential collection, shell history harvesting, and backdoor installation, then exfiltrates the stolen data to a Telegram bot. Researchers also linked the campaign to LaunchAgent persistence and a backdoor called goyim derived largely from GSocket tooling. ClickLock does not rely on a software exploit or privilege escalation; instead, it abuses user execution and suppresses defenses by repeatedly killing visible applications and NotificationCenter, sometimes every 210 milliseconds, until victims enter their macOS password and approve Keychain access. Apple separately published guidance warning that scammers increasingly use websites, chat agents, messaging platforms, and email to socially engineer Mac users into pasting unsafe Terminal commands, and said macOS may warn or block commands and scripts associated with known malware. Apple said such alerts mean the Mac has not yet been harmed and advised users not to run untrusted commands or scripts unless they fully trust the source.

Jul 20
Macrumors

'ClickLock' Malware Coerces Mac Users Into Giving Up Passwords - MacRumors

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.