< Back to all clusters
[TECHNOLOGY] · 2 sources

started · updated

MacSync Stealer malware targets macOS users via rotating domains

Microsoft Defender Experts have identified a sophisticated macOS information-stealing malware known as MacSync Stealer. The malware utilizes a rotating network of more than 30 domains to evade traditional domain-based blocking. Instead of relying on static indicators, security researchers are focusing on the malware’s consistent behavioral patterns to detect attacks.

MacSync Stealer typically spreads through ClickFix social engineering scams. Victims are tricked into pasting commands into their Terminal, which triggers an interactive zsh shell. This shell uses native utilities like curl, Base64, and gunzip to download and execute malicious payloads. The malware also abuses osascript to bridge AppleScript and shell commands, allowing it to perform actions such as file creation, deletion, and network communication.

The malware targets high-value data, including macOS Keychain material, browser credentials, cookies, SSH keys, AWS credentials, and cryptocurrency wallet information. It also scans for sensitive files like PDFs and DOCX documents. To avoid detection, the malware stages stolen data in temporary directories, compresses it into archives, and exfiltrates it in chunks via HTTP PUT requests before cleaning up its traces.

Entities

Apple · Expel · MacSync Stealer · Microsoft · SynkLoader