MacSync Stealer: SEO Poisoning and ClickFix-Based macOS Malware Delivery Chain
ID: a9fa95a1-3761-5e0e-a1fa-03b74eafa794
STIX ID: report--a9fa95a1-3761-5e0e-a1fa-03b74eafa794
Feed Name: CloudSEK Blog
CloudSEK analysts describe a multi-stage macOS campaign delivering "MacSync Stealer" via SEO-poisoned search results and ClickFix-style social engineering that tricks users into executing an obfuscated Terminal command. The chain fetches a staged zsh loader which runs AppleScript payloads to harvest browser credentials, crypto wallets (including desktop and extension data), SSH and cloud keys, and user documents, compresses and exfiltrates the data via chunked HTTP PUTs, and attempts post-compromise tampering of Ledger Live to enable long-term financial manipulation; the report includes domains, file IOCs, and defensive guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
