Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [ACTIVE] · [TECHNOLOGY]
7 clusters · 19 sources · 50 days · First seen · Last updated
macOS malware and infostealer campaigns
Overview
Security researchers have identified distinct macOS malware campaigns targeting user data and credentials. One campaign, dubbed ‘MacSync’ by Huntress, uses fraudulent Claude Code installation guides hosted on the legitimate claude.ai platform via Anthropic’s chat-sharing feature. By utilizing paid Google advertisements and deceptive display names like ‘Apple Support’, the attackers direct users to execute commands in the Terminal. This six-stage malware chain installs a stealer and a remote access Trojan, ultimately replacing legitimate cryptocurrency wallet applications with Trojanized versions to harvest seed phrases.
Recent analysis by Microsoft Defender Experts has expanded on the ‘MacSync Stealer’ capabilities, noting it utilizes a rotating network of more than 30 domains to evade domain-based blocking. The malware often spreads via ‘ClickFix’ social engineering scams that trick victims into pasting commands into their Terminal, triggering an interactive zsh shell. This shell uses native utilities like curl, Base64, and gunzip to execute payloads, while abusing osascript to perform file operations and network communication.
In September 2026, researchers noted an upgraded MacSync version that utilizes a distraction technique: after obtaining administrator passwords, the malware displays a fake ‘app is damaged’ notification to trick users into moving the app to the trash while the malware operates in the background. This version also targets device hardware data and SSH/ZSH configurations. Kaspersky has reported that MacSync has evolved to utilize public iCloud calendar entries in .ics format to host malicious commands and archives, leveraging legitimate Apple infrastructure to evade detection. The malware includes an Objective-C backdoor disguised as the macOS Finder to establish persistence and can deploy malicious browser add-ons to replace legitimate cryptocurrency wallet extensions. Beyond cryptocurrency, it targets macOS Keychain material, browser credentials, SSH, AWS, and Kubernetes configurations.
Entities
Timeline
-
2 days ago
[TECHNOLOGY] 2 sourcesMacSync malware evolves with backdoor and iCloud calendar exploitationA new version of the MacSync malware for macOS has been discovered, combining an infostealer with a backdoor module that exploits public iCloud calendars to deliver malicious payloads.
-
5 days ago
[TECHNOLOGY] 5 sourcesMacSync malware uses iCloud calendars to infect macOSMacSync malware has evolved to use public iCloud calendar events to deliver payloads and commands to macOS systems, combining social engineering with a new Objective-C backdoor disguised as Finder.
-
10 days ago
[TECHNOLOGY] 3 sourcesMacSync malware targets macOS users with new infostealer and backdoorKaspersky has discovered an upgraded MacSync malware for macOS that uses fake “app is damaged” alerts to distract users while stealing credentials, crypto assets, and browser data via a backdoor.
-
12 days ago
[TECHNOLOGY] 4 sourcesCybersecurity researchers warn of new malware targeting cryptocurrency usersCybercriminals are using MacSync malware on macOS and fake AI trading agents on Windows to steal cryptocurrency credentials and replace legitimate wallet extensions with malicious clones.
-
about 1 month ago
[TECHNOLOGY] 2 sourcesAmnesiaStealer malware targets macOS users via fake GitHub pagesA new macOS malware named AmnesiaStealer is targeting Chromium-based browsers via fake GitHub pages and ClickFix social engineering attacks to steal credentials and session cookies.
-
about 1 month ago
[TECHNOLOGY] 2 sourcesMacSync Stealer malware targets macOS users via rotating domainsMicrosoft has identified MacSync Stealer, a macOS malware using over 30 rotating domains to steal credentials, SSH keys, and cloud access via social engineering and native terminal commands.
-
about 2 months ago
[TECHNOLOGY] 3 sourcesMacSync malware targets macOS users via fake Claude Code guidesA sophisticated macOS malware campaign called MacSync uses fake Claude Code installation guides on claude.ai to steal cryptocurrency by hijacking Ledger and Trezor wallet apps.
Sources
ad-hoc-news.de · ambcrypto.com · cajnewsafrica.com · coinedition.com · cybernoz.com · cybersecuritynews.com · gamemag.it · it-boltwise.de · it-daily.net · ithome.com · m.jpnn.com · ourdailynewsonline.com · pcauthority.com.au · pemilu2024.harianjogja.com · phonetoday.it · punto-informatico.it · sempreupdate.com.br · techcoffeehouse.com · tomshw.it
This summary has been updated 5 times: see revision history