MacSync Stealer RAT Targets macOS With Credential Theft and Remote Access Capabilities
ID: 9563ebea-e16c-5bc3-88e5-d64628ad5a81
STIX ID: report--9563ebea-e16c-5bc3-88e5-d64628ad5a81
Feed Name: Cyber Press
Huntress researchers documented MacSync, a sophisticated six-stage macOS threat delivered via poisoned AI-chatbot/advertising pages that persuades users to run an obfuscated curl command; the loader fetches staged components that harvest keychain secrets and browser credentials, install a persistent Mach-O RAT via a LaunchAgent, obtain screen-capture permissions, and trojanize hardware wallet companion apps to phish seed phrases, with active infrastructure (Cloudflare-fronted domains and hardcoded IPs) and ties to the AMOS/Atomic Stealer lineage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
