Skip to content

MacSync

MacSync is a macOS information-stealing malware family offered under a malware-as-a-service model.

Profile source: Mallory opens in a new tab

MacSync

Family profile

MacSync is a macOS information-stealing malware family offered under a malware-as-a-service model. First advertised in 2025 as Mac.c, it was subsequently renamed MacSync. It targets both Intel-based and Apple Silicon Macs, with campaigns focused on developers, cryptocurrency users, and other IT-associated users. Distribution methods include ClickFix lures, malicious advertisements, cracked software, and fraudulent applications packaged in DMG disk images. Campaigns have impersonated cryptocurrency wallets and used shared AI-platform pages to persuade users to execute malicious Terminal commands. MacSync has also been deployed in PasteSwitch malvertising activity.

An updated variant observed in September 2026 combines a Swift-based infostealer with an Objective-C backdoor and uses multistage binary loaders and droppers. Some infection chains retrieve shell commands concealed in public iCloud Calendar event descriptions and download subsequent application bundles from iCloud infrastructure. Evasion measures include removal of macOS quarantine metadata, encrypted payload delivery, in-memory execution, virtual-machine checks, debugger blocking, and deletion of temporary artifacts and logs. Module delivery uses Curve25519 key exchange and AES-GCM encryption.

MacSync uses fraudulent administrator-password dialogs and validates captured passwords through macOS authentication interfaces. It collects browser histories, cookies, saved credentials, cryptocurrency-wallet application and extension data, Telegram data and sessions, macOS Keychain files, device credentials, and system information. It also targets SSH keys, cloud and developer configurations, Git and Kubernetes data, and shell-command histories, exfiltrating collected information to attacker infrastructure.

The backdoor masquerades as Finder and establishes persistence through LaunchAgents, shell-startup modifications, and global Git hooks. Restoration routines recover deleted components, while termination of macOS notification processes conceals persistence-related alerts. It can execute attacker-supplied AppleScript, collect and upload additional files, deploy browser extensions, and replace installed Ledger wallet software with an attacker-provided version.

Capabilities

  • Credential Theft
  • Crypto Theft
  • Defense Evasion
  • Exfiltration
  • Persistence
  • Post Exploitation
  • Reconnaissance
  • Session Hijacking

Observed infrastructure

Last seven days

First activity
Oct 1, 2026
Last activity
Oct 1, 2026
Feed role
Distribution
Host form
0 IP / 1 hostnames

Samples

Recent associated samples

Exploited software

Vulnerabilities linked to MacSync

1 CVEs

MITRE ATT&CK

MacSync in ATT&CK

82 distinct techniques

Techniques

82 techniques
T1547.015 Login Items T1204.002 Malicious File T1562.001 Disable or Modify Tools T1027 Obfuscated Files or Information T1056 Input Capture T1040 Network Sniffing T1574 Hijack Execution Flow T1546 Event Triggered Execution T1497 Virtualization/Sandbox Evasion T1560 Archive Collected Data T1555.001 Keychain T1552.001 Credentials In Files T1102.001 Dead Drop Resolver T1573 Encrypted Channel T1552.004 Private Keys T1555.003 Credentials from Web Browsers T1036 Masquerading T1176 Software Extensions T1059.004 Unix Shell T1102 Web Service T1140 Deobfuscate/Decode Files or Information T1543.001 Launch Agent T1552.005 Cloud Instance Metadata API T1036.005 Match Legitimate Resource Name or Location T1552.003 Shell History T1056.002 GUI Input Capture T1059.002 AppleScript T1539 Steal Web Session Cookie T1553.001 Gatekeeper Bypass T1573.001 Symmetric Cryptography T1497.001 System Checks T1041 Exfiltration Over C2 Channel T1560.001 Archive via Utility T1566 Phishing T1546.004 Unix Shell Configuration Modification T1622 Debugger Evasion T1620 Reflective Code Loading T1005 Data from Local System T1082 System Information Discovery T1070.004 File Deletion T1037.004 RC Scripts T1105 Ingress Tool Transfer T1059.007 JavaScript T1071.001 Web Protocols T1070.001 Clear Windows Event Logs T1555 Credentials from Password Stores T1204 User Execution T1074.001 Local Data Staging T1564.001 Hidden Files and Directories T1070.006 Timestomp T1070 Indicator Removal T1057 Process Discovery T1546.013 PowerShell Profile T1083 File and Directory Discovery T1204.001 Malicious Link T1078 Valid Accounts T1204.004 Malicious Copy and Paste T1583.008 Malvertising T1497.003 Time Based Checks T1003 OS Credential Dumping T1113 Screen Capture T1056.001 Keylogging T1074 Data Staged T1030 Data Transfer Size Limits T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol T1566.002 Spearphishing Link T1020 Automated Exfiltration T1518 Software Discovery T1528 Steal Application Access Token T1567 Exfiltration Over Web Service T1649 Steal or Forge Authentication Certificates T1583 Acquire Infrastructure T1219 Remote Access Tools T1098.004 SSH Authorized Keys T1552 Unsecured Credentials T1216.002 SyncAppvPublishingServer T1053 Scheduled Task/Job T1598 Phishing for Information T1059 Command and Scripting Interpreter T1583.001 Domains T1053.005 Scheduled Task T1548 Abuse Elevation Control Mechanism

Reporting

Research mentioning MacSync

Sep 28
Huntress

Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix | Huntress

Attackers abused ChatGPT Custom GPT pages branded as “Plus 5.6” and promoted them through sponsored Google Search results to impersonate a legitimate ChatGPT model. Victims were redirected to a fake backup domain hosting a Google Sites page styled as ChatGPT and Cloudflare verification prompts; the ClickFix lure instructed them to run PowerShell, silently installing a malicious MSI and a sophisticated remote-access trojan (RAT). Huntress handled at least 40 incidents tied to the Google Sites domain, including two confirmed infections originating from Custom GPT lures, and observed replacement lures after the original was removed. The campaign used signed third-party software for DLL sideloading and layered persistence. An initial variant abused Canon-signed CaptureOnTouch components, concealed its loader in a WAV file, and created Run-key and scheduled-task persistence labeled “Canon Configuration Reader.” A second variant preserved the RAT framework but used Stardock-signed DeElevate64.exe, a modified DeElevator64.dll, and a NuGet package carrier, establishing persistence as “Stardock DeElevation Tool.” Organizations should treat sponsored AI-tool search results and browser verification prompts that require shell commands as high-risk social-engineering activity.

Sep 23
Help Net Security

DarkMe RAT trades zero-days for plain phishing emails - Help Net Security

A new DarkMe remote-access Trojan campaign has shifted from the exploit-led delivery associated with Water Hydra to straightforward phishing. Lures disguised as image links served executable .PIF files, which launched a remote MSI installer and a multistage Visual Basic 6 loader chain. The chain registers a COM object and invokes it through rundll32.exe /sta {CLSID}, checks for sandbox-like processes, creates persistence through a custom Locked:// URI handler, and process-hollows the signed Microsoft clspack.exe binary. The final payload combines remote-access and infostealing functions: it can collect cryptocurrency-wallet data, take screenshots, enumerate installed antivirus products, manipulate files, and run commands. It communicates over custom TCP command-and-control on port 7712; observed infrastructure included thatawful[.]boutique resolving to 67.43.50[.]11:7712. Organizations should block the identified infrastructure, investigate .PIF downloads and suspicious remote MSI execution, and hunt for the rundll32.exe /sta COM-launch pattern and unauthorized Locked:// registry protocol handlers.

Sep 23
Itsecurityguru

Zero-day hackers ditch exploits for a fake image file in new DarkMe campaign - IT Security Guru

Sep 22
Huntress

DarkMe RAT: A VB6 APT Trojan Turned Conventional Infostealer | Huntress

Sep 14
Huntress

Google Doc Sidebar Sends Mac and Windows Users Down Different Paths to Malware | Huntress

A threat actor impersonated a CoinDesk marketing executive in X direct messages, using post-Black Hat and DEFCON cryptocurrency-conference lures to target security researchers. The messages linked to legitimate Google Docs containing container-bound Google Apps Script that profiled visitors and sent their IP address, geolocation, browser details, and cryptocurrency-wallet-extension data to the operator through Telegram. The campaign routed victims to operating-system-specific malware: macOS users received a variant of the AMOS infostealer, while Windows users were served an encoded PowerShell loader chain and installers signed with three stolen or fraudulently issued certificates. Recovered Windows components included a malicious NetSupport Manager deployment, a persistent rogue local certificate authority capable of TLS interception, and a Ledger-wallet-focused implant. Russian-language comments and C2 artifacts indicate the operator may be Russian-speaking, but no threat group has been attributed.

Sep 14
Malware News

HBO Max ads on a compromised Reddit account exposed a massive PasteSwitch ClickFix operation - Malware Analysis - Malware Analysis, News and Indicators

Attackers compromised the verified Reddit account u/hbomax and used it to run 108 malicious advertisements over roughly 48 hours. The ads impersonated HBO Max, AI-development tools, and macOS utilities, directing targets into a ClickFix campaign researchers call PasteSwitch that persuaded victims to copy and execute commands in a terminal or Windows Run dialog. The copied commands selected payloads by operating system: macOS victims received MacSync and AMOS Helper stealers, while a Windows InstallFix chain loaded Amatera Stealer in memory. The campaign also deployed fake cryptocurrency wallets and crypto clippers, using direct-to-IP TLS communications and Binance Smart Chain smart contracts to rotate clipper command-and-control domains. Reddit paused the malicious ads and began an internal investigation to secure the compromised account.

Sep 14
Hudsonrock

HBO Max ads on a compromised Reddit account exposed a massive PasteSwitch ClickFix operation | Hudson Rock

Sep 8
Malware News

MacSync: The Evasive macOS Stealer Exploiting ClickFix Lures - Malware News - Malware Analysis, News and Indicators

MacSync, a malware-as-a-service macOS stealer and remote-access stager, is being distributed through ClickFix social engineering, SEO poisoning, malvertising, compromised websites, and fake software or AI installers that prompt victims to run Terminal commands. Its native 64-bit Mach-O stager daemonizes itself, XOR-decrypts its configuration, downloads an AppleScript stealer from command-and-control (C2) infrastructure, and executes it in memory through osascript. The malware targets Keychain records, browser credentials and cookies, SSH keys, messaging sessions, cloud credentials, cryptocurrency wallets, and sensitive files. It archives collected data and exfiltrates it in 10 MB HTTP PUT chunks before deleting local staging artifacts; analyzed samples used drivinguber.com as primary C2 infrastructure and newsinweb.com-derived hosts as fallbacks. Public reporting associates MacSync with the earlier Mac.C Stealer and the developer identity “Mentalpositive,” though Russian-language artifacts do not substantiate attribution to a particular actor, syndicate, or affiliate campaign.