Something Phishy in the /tmp Folder
ID: e078cf6e-6126-5019-809f-9ef16926d522
STIX ID: report--e078cf6e-6126-5019-809f-9ef16926d522
Feed Name: Huntress Blog
Threat Score
A macOS infostealer named **MacSync** used a fake “macOS Protection Service” prompt to trick a user into unlocking the Keychain, harvested credentials, browser cookies, and crypto wallets into /tmp/salmonela, zipped the stash and attempted to POST it to a C2 server, but Huntress Managed EDR and a 24/7 SOC detected and isolated the host before data was successfully exfiltrated.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
