logo

SEO Poisoning and “ClickFix” Tactics: The Rise of MacSync Stealer

ID: c096ba44-2dc4-5f6a-8acc-90eb2ea82ffe

STIX ID: report--c096ba44-2dc4-5f6a-8acc-90eb2ea82ffe

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-03-23

Date Updated: 2026-04-23

Author: Ddos

...
...

CloudSEK identified a macOS-focused campaign delivering MacSync Stealer by poisoning search results for popular book PDFs and luring users to fake "human verification" pages that instruct victims to paste a Terminal command; the Base64-encoded payload fetches and runs a remote loader which quickly harvests browser credentials and cookies, copies browser and desktop crypto wallets, exfiltrates system keys and configuration files, and can tamper with Ledger Live to enable financial theft.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.