MacSync Stealer: How a Google Search for Claude Led to a macOS Infostealer
ID: 333ba540-3e69-5ed6-971e-29e85f1600f8
STIX ID: report--333ba540-3e69-5ed6-971e-29e85f1600f8
Feed Name: Huntress Blog
Huntress analyzed a malvertising campaign that redirected victims to a malicious shared conversation on claude.ai which instructed users to run a curl/zsh loader; this loader deployed a six-stage macOS threat called MacSync that uses in-memory AppleScript, a Mach-O RAT, a signed helper to obtain screen-recording TCC permissions, and trojanized wallet apps to exfiltrate cookies, passwords, keychain items, Telegram sessions, SSH/cloud keys, and cryptocurrency recovery phrases. The report includes technical breakdowns of each stage, persistence mechanisms, a C2 IP (85.206.161.241:8443), detection suggestions, and emphasizes user caution against pasting opaque base64/one-liner commands into Terminal.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
