MacSync macOS Infostealer Leverage ClickFix-style Attack to Trick Users Pasting a Single Terminal Command
ID: b45bcf6d-49b8-510e-b6da-3ee1437368bf
STIX ID: report--b45bcf6d-49b8-510e-b6da-3ee1437368bf
Feed Name: cybersecurityNews.com
MacSync is a script-driven macOS infostealer (offered as Malware-as-a-Service) that uses deceptive landing pages and a one-line Terminal command to bypass Gatekeeper and deploy a Zsh loader and AppleScript payload; it harvests cryptocurrency-related data (browser wallet extensions, desktop wallets, seed phrases, private keys), SSH keys, Keychain entries and credentials, and can trojanize hardware wallet apps to capture PINs and recovery phrases, with multiple rotating C2 domains indicating an active, scalable campaign.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
