logo

MacSync Stealer: How a Google Search for Claude Led to a macOS Infostealer

ID: 333ba540-3e69-5ed6-971e-29e85f1600f8

STIX ID: report--333ba540-3e69-5ed6-971e-29e85f1600f8

Feed Name: Huntress Blog

Threat Score
78/100

Date Published: 2026-08-17

Date Updated: 2026-08-19

...
...

Huntress analyzed a malvertising campaign that redirected victims to a malicious shared conversation on claude.ai which instructed users to run a curl/zsh loader; this loader deployed a six-stage macOS threat called MacSync that uses in-memory AppleScript, a Mach-O RAT, a signed helper to obtain screen-recording TCC permissions, and trojanized wallet apps to exfiltrate cookies, passwords, keychain items, Telegram sessions, SSH/cloud keys, and cryptocurrency recovery phrases. The report includes technical breakdowns of each stage, persistence mechanisms, a C2 IP (85.206.161.241:8443), detection suggestions, and emphasizes user caution against pasting opaque base64/one-liner commands into Terminal.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.