logo

Something Phishy in the /tmp Folder

ID: e078cf6e-6126-5019-809f-9ef16926d522

STIX ID: report--e078cf6e-6126-5019-809f-9ef16926d522

Feed Name: Huntress Blog

Threat Score
65/100

Date Published: 2026-03-18

Date Updated: 2026-04-28

...
...

A macOS infostealer named **MacSync** used a fake “macOS Protection Service” prompt to trick a user into unlocking the Keychain, harvested credentials, browser cookies, and crypto wallets into /tmp/salmonela, zipped the stash and attempted to POST it to a C2 server, but Huntress Managed EDR and a 24/7 SOC detected and isolated the host before data was successfully exfiltrated.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.