Reverse Engineering the Six Stages of MacSync Stealer and RAT
ID: 603d9d06-2fd3-5a72-833a-c4e2976f4974
STIX ID: report--603d9d06-2fd3-5a72-833a-c4e2976f4974
Feed Name: Huntress Blog
MacSync is a multi-stage macOS infostealer campaign delivered via poisoned (paid) search results pointing to a weaponised Claude.ai shared conversation; a user-pasted curl|zsh one-liner fetched an in-memory AppleScript stealer that coerced Full Disk Access, harvested browser cookies, keychain secrets and a validated account password, then installed a persistent Mach‑O RAT and a signed Screen Recording helper, and finally trojanised desktop wallet apps to phish seed phrases — producing irreversible crypto theft. The report includes recovered payloads, C2 and drop infrastructure, host artifacts, file hashes, MITRE mappings, and behavioral detection guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
