Last seven days
- First activity
- Aug 22, 2026
- Last activity
- Aug 22, 2026
- Feed role
- C2 / Distribution
- Host form
- 0 IP / 3 hostnames
MacSync Stealer is a macOS-focused infostealer used in socially engineered infection chains that rely on users executing attacker-supplied Terminal commands, most notably through ClickFix-style lures.
Profile source: Mallory opens in a new tabMacSync
MacSync Stealer is a macOS-focused infostealer used in socially engineered infection chains that rely on users executing attacker-supplied Terminal commands, most notably through ClickFix-style lures. Observed campaigns have used counterfeit software-installation guidance, fake GitHub-themed pages, and malvertising-driven prompts that instruct victims to paste a curl command into zsh or Terminal, after which native macOS tools and AppleScript-assisted execution retrieve, unpack, and launch the payload.
The malware is designed to collect high-value data from compromised Mac systems. Reported collection targets include macOS Keychain material, browser credentials, cookies, session data, IndexedDB and LevelDB content, browser profile artifacts, Safari data, Apple Notes, Telegram sessions, SSH keys, cloud and developer secrets such as AWS credentials and Kubernetes configurations, and sensitive user documents. It also targets cryptocurrency-related data, including wallet artifacts, hardware-wallet companion data, and in some reporting, wallet recovery phrases through tampering with wallet applications.
MacSync Stealer stages harvested data in temporary locations, compresses it into an archive, splits the archive into chunks, and exfiltrates the results over HTTP PUT using curl. It has also been observed deleting temporary staging material and other artifacts after upload. Some reporting further describes a broader multi-component intrusion set associated with MacSync that includes persistence via a LaunchAgent, a remote-access component capable of interactive shell access and file transfer, screen-capture functionality after user consent, and modification of cryptocurrency wallet applications to phish for seed phrases.
The malware has been tracked through durable behavioral patterns rather than static infrastructure because its operators rotate delivery and command infrastructure rapidly. MacSync Stealer has been discussed alongside other macOS stealers such as Atomic Stealer (AMOS), CrashStealer, and AmnesiaStealer due to overlapping objectives and shared lure templates, but available reporting does not conclusively attribute it to a named threat actor. It primarily targets macOS users and is relevant to environments where browser-stored credentials, developer secrets, cloud access material, and cryptocurrency assets are present.
C2 tracking
Derp observations, rolling seven-day window
Samples
Exploited software
MITRE ATT&CK
Reporting
A malvertising campaign used sponsored Google search results for Anthropic's Claude to lure macOS users to a legitimate shared conversation page on claude.ai, where they were socially engineered into running a malicious terminal command. Huntress reported that the command fetched MacSync, a multi-stage macOS infostealer and remote access trojan that chains a zsh loader, in-memory AppleScript theft, a persistent Mach-O RAT, and a helper component designed to abuse Screen Recording permissions. The malware was built to steal a wide range of data from infected Macs, including browser data, Keychain secrets, saved passwords, Telegram sessions, SSH and cloud credentials, and cryptocurrency wallet recovery phrases. The operation also used repeated TCC permission prompts, fake "Apple Support" messaging, and trojanized cryptocurrency wallet applications to deepen access, maintain persistence, and expand theft beyond initial credential harvesting.
Microsoft reported that a macOS-focused ClickFix campaign evolved from openly serving fake download pages to using server-side browser fingerprinting that shows the malicious lure mainly to likely macOS victims. The operation used more than 250 look-alike domains, often following dictionary-style naming patterns that included the token file, and presented spoofed GitHub-themed pages with a fake Download for macOS prompt. Victims were tricked into pasting a Terminal command that fetched remote scripts and installed infostealers including Atomic Stealer (AMOS) and MacSync. The gating logic collected browser, hardware, and anti-analysis signals before deciding whether to deliver the lure, including navigator data, WebGL GPU details, timezone, iframe status, touch support, console serialization behavior, and prototype-tamper checks; non-qualifying visitors were sent blank or benign decoy pages. Separate IOC material tied the same broader activity to additional macOS infostealer infrastructure, including SHub Stealer, suspected delivery and command-and-control domains, a SHA-256 sample hash, and capabilities such as screenshot capture, file download, command execution, and self-deletion, reinforcing that the campaign relied on rotating lure domains and stealthy staging to target macOS users.
Researchers reported continued activity around CastleLoader/CastleBot malware delivery chains alongside a resurgence of KongTuke, with both threats relying heavily on social-engineering lures and staged payload delivery. Red Canary said CastleLoader remained active since early 2025 and was commonly delivered through paste-and-run fake CAPTCHA or impersonation websites, while Trend Micro documented KongTuke abusing compromised WordPress sites in ClickFix-style infection flows. The campaigns reflect a broader shift toward user-assisted execution, where victims are tricked into launching malicious commands that initiate multi-stage malware retrieval. Technical analysis from IBM and Splunk tied the Castle ecosystem to a malware-as-a-service operation and detailed the tooling used after execution, including use of finger.exe to fetch batch commands, portable Python interpreters as a bring-your-own-interpreter technique, multilayer-obfuscated Python loaders, RC4-encrypted payload retrieval, and process injection into python.exe. Splunk's review of Castle RAT highlighted the client malware's tactics and ATT&CK-mapped behavior, while Red Canary noted anti-analysis checks, C2-based tasking, and detection opportunities such as repeated caret obfuscation in cmd.exe command lines. Together, the reporting shows an active loader-and-RAT ecosystem being distributed through fake verification pages and compromised web infrastructure.
Researchers reported a new macOS infostealer dubbed ClickLock Stealer that tricks users into pasting a malicious bash command into Terminal through ClickFix-style pages masquerading as Cloudflare verification prompts. Group-IB said the malware has been active since at least late May and has targeted at least 100 users in 33 countries, with more than half of victims in Europe. Once launched, the malware downloads multiple payloads for browser credential theft, cryptocurrency wallet theft, Keychain theft, password manager and FileZilla credential collection, shell history harvesting, and backdoor installation, then exfiltrates the stolen data to a Telegram bot. Researchers also linked the campaign to LaunchAgent persistence and a backdoor called goyim derived largely from GSocket tooling. ClickLock does not rely on a software exploit or privilege escalation; instead, it abuses user execution and suppresses defenses by repeatedly killing visible applications and NotificationCenter, sometimes every 210 milliseconds, until victims enter their macOS password and approve Keychain access. Apple separately published guidance warning that scammers increasingly use websites, chat agents, messaging platforms, and email to socially engineer Mac users into pasting unsafe Terminal commands, and said macOS may warn or block commands and scripts associated with known malware. Apple said such alerts mean the Mac has not yet been harmed and advised users not to run untrusted commands or scripts unless they fully trust the source.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.