Last seven days
- First activity
- Sep 2, 2026
- Last activity
- Sep 7, 2026
- Feed role
- C2 / Distribution
- Host form
- 0 IP / 5 hostnames
MacSync Stealer is a macOS-exclusive information-stealing malware family offered under a malware-as-a-service model.
Profile source: Mallory opens in a new tabMacSync
MacSync Stealer is a macOS-exclusive information-stealing malware family offered under a malware-as-a-service model. It is delivered primarily through ClickFix social engineering, search-engine malvertising, SEO poisoning, compromised websites, and fraudulent software or AI-service installation pages. Lures impersonate well-known software, collaboration, AI, cloud, and cryptocurrency services and persuade victims to paste attacker-supplied commands into Terminal. Public reporting has linked the family to the earlier Mac.C Stealer and a developer identity known as Mentalpositive, although available evidence does not support definitive attribution to a specific threat actor or syndicate.
MacSync uses native macOS tooling and AppleScript-assisted execution to retrieve dynamically supplied payloads, collect data, and communicate with command-and-control infrastructure. Its native stager can detach from the originating Terminal session, obfuscate embedded configuration, execute remotely retrieved AppleScript without saving it as a script file, and suppress console output. The stealer targets macOS Keychain material, saved browser credentials, cookies and other browser-session data, SSH keys, cloud credentials, messaging-session data, Apple Notes, Safari data, Kubernetes configuration, sensitive documents, and cryptocurrency wallet artifacts. It packages stolen information into an archive, uploads it in chunks through HTTP PUT requests, and removes temporary staging material after successful exfiltration.
Observed MacSync chains can deploy a persistent remote-access component through a LaunchAgent, enabling interactive shell access, command execution, and file transfer. Other components request sensitive macOS permissions, including Screen Recording, and can modify cryptocurrency wallet applications or extensions to solicit wallet recovery phrases. Reporting has identified activity affecting users in technology and software organizations, cryptocurrency and Web3 communities, financial services, remote-work environments, and government or defense-related roles.
C2 tracking
Derp observations, rolling seven-day window
Samples
Exploited software
MITRE ATT&CK
Reporting
MacSync, a malware-as-a-service macOS stealer and remote-access stager, is being distributed through ClickFix social engineering, SEO poisoning, malvertising, compromised websites, and fake software or AI installers that prompt victims to run Terminal commands. Its native 64-bit Mach-O stager daemonizes itself, XOR-decrypts its configuration, downloads an AppleScript stealer from command-and-control (C2) infrastructure, and executes it in memory through osascript. The malware targets Keychain records, browser credentials and cookies, SSH keys, messaging sessions, cloud credentials, cryptocurrency wallets, and sensitive files. It archives collected data and exfiltrates it in 10 MB HTTP PUT chunks before deleting local staging artifacts; analyzed samples used drivinguber.com as primary C2 infrastructure and newsinweb.com-derived hosts as fallbacks. Public reporting associates MacSync with the earlier Mac.C Stealer and the developer identity “Mentalpositive,” though Russian-language artifacts do not substantiate attribution to a particular actor, syndicate, or affiliate campaign.
A malvertising campaign used sponsored Google search results for Anthropic's Claude to lure macOS users to a legitimate shared conversation page on claude.ai, where they were socially engineered into running a malicious terminal command. Huntress reported that the command fetched MacSync, a multi-stage macOS infostealer and remote access trojan that chains a zsh loader, in-memory AppleScript theft, a persistent Mach-O RAT, and a helper component designed to abuse Screen Recording permissions. The malware was built to steal a wide range of data from infected Macs, including browser data, Keychain secrets, saved passwords, Telegram sessions, SSH and cloud credentials, and cryptocurrency wallet recovery phrases. The operation also used repeated TCC permission prompts, fake "Apple Support" messaging, and trojanized cryptocurrency wallet applications to deepen access, maintain persistence, and expand theft beyond initial credential harvesting.
Microsoft reported that a macOS-focused ClickFix campaign evolved from openly serving fake download pages to using server-side browser fingerprinting that shows the malicious lure mainly to likely macOS victims. The operation used more than 250 look-alike domains, often following dictionary-style naming patterns that included the token file, and presented spoofed GitHub-themed pages with a fake Download for macOS prompt. Victims were tricked into pasting a Terminal command that fetched remote scripts and installed infostealers including Atomic Stealer (AMOS) and MacSync. The gating logic collected browser, hardware, and anti-analysis signals before deciding whether to deliver the lure, including navigator data, WebGL GPU details, timezone, iframe status, touch support, console serialization behavior, and prototype-tamper checks; non-qualifying visitors were sent blank or benign decoy pages. Separate IOC material tied the same broader activity to additional macOS infostealer infrastructure, including SHub Stealer, suspected delivery and command-and-control domains, a SHA-256 sample hash, and capabilities such as screenshot capture, file download, command execution, and self-deletion, reinforcing that the campaign relied on rotating lure domains and stealthy staging to target macOS users.
Researchers reported continued activity around CastleLoader/CastleBot malware delivery chains alongside a resurgence of KongTuke, with both threats relying heavily on social-engineering lures and staged payload delivery. Red Canary said CastleLoader remained active since early 2025 and was commonly delivered through paste-and-run fake CAPTCHA or impersonation websites, while Trend Micro documented KongTuke abusing compromised WordPress sites in ClickFix-style infection flows. The campaigns reflect a broader shift toward user-assisted execution, where victims are tricked into launching malicious commands that initiate multi-stage malware retrieval. Technical analysis from IBM and Splunk tied the Castle ecosystem to a malware-as-a-service operation and detailed the tooling used after execution, including use of finger.exe to fetch batch commands, portable Python interpreters as a bring-your-own-interpreter technique, multilayer-obfuscated Python loaders, RC4-encrypted payload retrieval, and process injection into python.exe. Splunk's review of Castle RAT highlighted the client malware's tactics and ATT&CK-mapped behavior, while Red Canary noted anti-analysis checks, C2-based tasking, and detection opportunities such as repeated caret obfuscation in cmd.exe command lines. Together, the reporting shows an active loader-and-RAT ecosystem being distributed through fake verification pages and compromised web infrastructure.
Researchers reported a new macOS infostealer dubbed ClickLock Stealer that tricks users into pasting a malicious bash command into Terminal through ClickFix-style pages masquerading as Cloudflare verification prompts. Group-IB said the malware has been active since at least late May and has targeted at least 100 users in 33 countries, with more than half of victims in Europe. Once launched, the malware downloads multiple payloads for browser credential theft, cryptocurrency wallet theft, Keychain theft, password manager and FileZilla credential collection, shell history harvesting, and backdoor installation, then exfiltrates the stolen data to a Telegram bot. Researchers also linked the campaign to LaunchAgent persistence and a backdoor called goyim derived largely from GSocket tooling. ClickLock does not rely on a software exploit or privilege escalation; instead, it abuses user execution and suppresses defenses by repeatedly killing visible applications and NotificationCenter, sometimes every 210 milliseconds, until victims enter their macOS password and approve Keychain access. Apple separately published guidance warning that scammers increasingly use websites, chat agents, messaging platforms, and email to socially engineer Mac users into pasting unsafe Terminal commands, and said macOS may warn or block commands and scripts associated with known malware. Apple said such alerts mean the Mac has not yet been harmed and advised users not to run untrusted commands or scripts unless they fully trust the source.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.