logo

MacSync Stealer Campaign Impacting U.S. SLTT macOS Users

ID: 8c76467e-4dd6-5ebb-890c-3a87d2417b4c

STIX ID: report--8c76467e-4dd6-5ebb-890c-3a87d2417b4c

Feed Name: CISecurity.org Insights Blog

Threat Score
78/100

Date Published: 2026-04-13

Date Updated: 2026-04-19

...
...

## Executive Summary CIS CTI details an active MacSync Stealer campaign targeting macOS users in U.S. State, Local, Tribal, and Territorial (SLTT) organizations that leverages SEO-poisoned search results and a ClickFix fake CAPTCHA to trick victims into running Base64-encoded Terminal commands that fetch a Zsh bootstrap and in-memory AppleScript payload; the malware exfiltrates browser credentials, wallets, Keychain and cloud credentials, and can trojanize Ledger applications to persistently capture seed phrases, with IOCs and API-key fingerprints identified for attribution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.