logo

MacSync macOS Infostealer Exploits ClickFix-style Attack to Trick Users with Single Terminal Command

ID: c603df3b-ae9a-52d3-9040-d0d58116b574

STIX ID: report--c603df3b-ae9a-52d3-9040-d0d58116b574

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-01-23

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

A sophisticated macOS infostealer campaign dubbed MacSync uses phishing redirects and a deceptive “Terminal installation” one-liner to install a multi-stage, script-driven payload that bypasses Gatekeeper. The AppleScript-based stealer exfiltrates browser profiles, Keychain contents, SSH/AWS/Kubernetes credentials, and cryptocurrency wallet data, and can persist by trojanizing Ledger and Trezor desktop apps to phish PINs and recovery phrases; multiple rotating C2 domains and unique build tokens indicate active, evolving operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.