< Back to situations

Monitor this situation.

[SITUATION] · [ACTIVE] · [TECHNOLOGY]

7 clusters · 19 sources · 50 days · First seen · Last updated

macOS malware and infostealer campaigns

Overview

Security researchers have identified distinct macOS malware campaigns targeting user data and credentials. One campaign, dubbed ‘MacSync’ by Huntress, uses fraudulent Claude Code installation guides hosted on the legitimate claude.ai platform via Anthropic’s chat-sharing feature. By utilizing paid Google advertisements and deceptive display names like ‘Apple Support’, the attackers direct users to execute commands in the Terminal. This six-stage malware chain installs a stealer and a remote access Trojan, ultimately replacing legitimate cryptocurrency wallet applications with Trojanized versions to harvest seed phrases.

Recent analysis by Microsoft Defender Experts has expanded on the ‘MacSync Stealer’ capabilities, noting it utilizes a rotating network of more than 30 domains to evade domain-based blocking. The malware often spreads via ‘ClickFix’ social engineering scams that trick victims into pasting commands into their Terminal, triggering an interactive zsh shell. This shell uses native utilities like curl, Base64, and gunzip to execute payloads, while abusing osascript to perform file operations and network communication.

In September 2026, researchers noted an upgraded MacSync version that utilizes a distraction technique: after obtaining administrator passwords, the malware displays a fake ‘app is damaged’ notification to trick users into moving the app to the trash while the malware operates in the background. This version also targets device hardware data and SSH/ZSH configurations. Kaspersky has reported that MacSync has evolved to utilize public iCloud calendar entries in .ics format to host malicious commands and archives, leveraging legitimate Apple infrastructure to evade detection. The malware includes an Objective-C backdoor disguised as the macOS Finder to establish persistence and can deploy malicious browser add-ons to replace legitimate cryptocurrency wallet extensions. Beyond cryptocurrency, it targets macOS Keychain material, browser credentials, SSH, AWS, and Kubernetes configurations.

Entities

Kaspersky · MacSync · Apple · macOS · iCloud

Timeline

  1. 2 days ago

    [TECHNOLOGY] 2 sources
    MacSync malware evolves with backdoor and iCloud calendar exploitation

    A new version of the MacSync malware for macOS has been discovered, combining an infostealer with a backdoor module that exploits public iCloud calendars to deliver malicious payloads.

  2. 5 days ago

    [TECHNOLOGY] 5 sources
    MacSync malware uses iCloud calendars to infect macOS

    MacSync malware has evolved to use public iCloud calendar events to deliver payloads and commands to macOS systems, combining social engineering with a new Objective-C backdoor disguised as Finder.

  3. 10 days ago

    [TECHNOLOGY] 3 sources
    MacSync malware targets macOS users with new infostealer and backdoor

    Kaspersky has discovered an upgraded MacSync malware for macOS that uses fake “app is damaged” alerts to distract users while stealing credentials, crypto assets, and browser data via a backdoor.

  4. 12 days ago

    [TECHNOLOGY] 4 sources
    Cybersecurity researchers warn of new malware targeting cryptocurrency users

    Cybercriminals are using MacSync malware on macOS and fake AI trading agents on Windows to steal cryptocurrency credentials and replace legitimate wallet extensions with malicious clones.

  5. about 1 month ago

    [TECHNOLOGY] 2 sources
    AmnesiaStealer malware targets macOS users via fake GitHub pages

    A new macOS malware named AmnesiaStealer is targeting Chromium-based browsers via fake GitHub pages and ClickFix social engineering attacks to steal credentials and session cookies.

  6. about 1 month ago

    [TECHNOLOGY] 2 sources
    MacSync Stealer malware targets macOS users via rotating domains

    Microsoft has identified MacSync Stealer, a macOS malware using over 30 rotating domains to steal credentials, SSH keys, and cloud access via social engineering and native terminal commands.

  7. about 2 months ago

    [TECHNOLOGY] 3 sources
    MacSync malware targets macOS users via fake Claude Code guides

    A sophisticated macOS malware campaign called MacSync uses fake Claude Code installation guides on claude.ai to steal cryptocurrency by hijacking Ledger and Trezor wallet apps.

Sources

ad-hoc-news.de · ambcrypto.com · cajnewsafrica.com · coinedition.com · cybernoz.com · cybersecuritynews.com · gamemag.it · it-boltwise.de · it-daily.net · ithome.com · m.jpnn.com · ourdailynewsonline.com · pcauthority.com.au · pemilu2024.harianjogja.com · phonetoday.it · punto-informatico.it · sempreupdate.com.br · techcoffeehouse.com · tomshw.it

This summary has been updated 5 times: see revision history