< Back to situation

[REVISION HISTORY]

macOS malware and infostealer campaigns

Updated 5 times since CLSTR started tracking revisions of this situation.

What changed

2026-09-21 07:19 UTC → 2026-09-25 11:02 UTC · added removed

Security researchers have identified distinct macOS malware campaigns targeting user data and credentials. One campaign, dubbed ‘MacSync’ by Huntress, uses fraudulent Claude Code installation guides hosted on the legitimate claude.ai platform via Anthropic’s chat-sharing feature. By utilizing paid Google advertisements and deceptive display names like ‘Apple Support’, the attackers direct users to execute commands in the Terminal. This six-stage malware chain installs a stealer and a remote access Trojan, ultimately replacing legitimate cryptocurrency wallet applications with Trojanized versions to harvest seed phrases. Recent analysis by Microsoft Defender Experts has expanded on the ‘MacSync Stealer’ capabilities, noting it utilizes a rotating network of more than 30 domains to evade domain-based blocking. The malware often spreads via ‘ClickFix’ social engineering scams that trick victims into pasting commands into their Terminal, triggering an interactive zsh shell. This shell uses native utilities like curl, Base64, and gunzip to execute payloads, while abusing osascript to perform file operations and network communication. Beyond cryptocurrency theft, the malware targets macOS Keychain material, browser credentials, SSH keys, AWS credentials, and sensitive documents like PDFs and DOCX files. Kaspersky has reported an updated version of the MacSync infostealer that may utilize public iCloud calendar entries to host malicious components. Once installed, it deploys an infostealer and a backdoor disguised as the Finder application, capable of harvesting browser histories, cookies, saved credentials, and data from Telegram and the device Keychain. In September 2026, researchers noted an upgraded MacSync version that uses utilizes a distraction technique: after obtaining administrator passwords, the malware displays a fake ‘app is damaged’ notification to trick users into moving the app to the trash while the malware operates in the background. This version also targets device hardware data and SSH/ZSH configurations. Separately, Jamf Threat Labs identified ‘AmnesiaStealer’, a multi-stage infostealer written Kaspersky has reported that MacSync has evolved to utilize public iCloud calendar entries in Rust. .ics format to host malicious commands and archives, leveraging legitimate Apple infrastructure to evade detection. The malware includes an Objective-C backdoor disguised as the macOS Finder to establish persistence and can deploy malicious browser add-ons to replace legitimate cryptocurrency wallet extensions. Beyond cryptocurrency, it targets macOS Keychain material, browser credentials, SSH, AWS, and Kubernetes configurations.

Versions

  1. 2026-09-25 11:02 UTC macOS malware and infostealer campaigns
  2. 2026-09-21 07:19 UTC macOS malware and infostealer campaigns
  3. 2026-09-18 04:12 UTC macOS malware and infostealer campaigns
  4. 2026-08-29 11:02 UTC macOS malware and infostealer campaigns
  5. 2026-08-22 14:36 UTC macOS malware and infostealer campaigns
  6. 2026-08-13 14:07 UTC macOS malware and infostealer campaigns

Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.