SEO Poisoning and “ClickFix” Tactics: The Rise of MacSync Stealer
ID: c096ba44-2dc4-5f6a-8acc-90eb2ea82ffe
STIX ID: report--c096ba44-2dc4-5f6a-8acc-90eb2ea82ffe
Feed Name: securityonline.info
CloudSEK identified a macOS-focused campaign delivering MacSync Stealer by poisoning search results for popular book PDFs and luring users to fake "human verification" pages that instruct victims to paste a Terminal command; the Base64-encoded payload fetches and runs a remote loader which quickly harvests browser credentials and cookies, copies browser and desktop crypto wallets, exfiltrates system keys and configuration files, and can tamper with Ledger Live to enable financial theft.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
