MacSync
malware · malware:macsync single-source
Six-stage macOS infostealer and remote-access tool analysed by Huntress, delivered through a sponsored search result leading to a publicly shared conversation page on the genuine claude.ai domain that instructs the victim to paste a curl one-liner into Terminal. Stages run a polymorphic zsh loader in memory, a server-side AppleScript stealer, a Mach-O remote-access tool persisting via a launch agent, a helper for the screen-recording permission and a set of wallet-application trojans; collection covers browser cookies and logins, keychain secrets, Telegram sessions, SSH and cloud keys (Huntress, 2026-08-17).
Story timeline
Every entry that names MacSync, newest first. Rows tagged mention only name it in passing: they are listed for completeness and add nothing to the action items, pivots or ATT&CK profile on this page.
- 2026-08-07The macOS ClickFix chain now qualifies visitors server-side before showing the lure, with anti-analysis probes that detect a console rather than a sandbox
- 2026-07-14CrashStealer, a native-C++ macOS infostealer using a notarized dropper and local dscl password validation to raid keychain, browsers and wallets
Entries about MacSync
No published entry is about this entity yet · the story timeline above lists the entries that mention it.
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
Where this entity is cited
Source distribution
- bleepingcomputer.com1 (33%)
- jamf.com1 (33%)
- microsoft.com1 (33%)
All cited sources (3)
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/security/new-crashstealer-malware-poses-as-apple-crash-reporting-tool/
- jamf.comJamf Threat Labshttps://www.jamf.com/blog/crashstealer-macos-infostealer-analysis/
- microsoft.comMicrosoft Threat Intelligencehttps://www.microsoft.com/en-us/security/blog/2026/08/05/macos-clickfix-campaign-learned-hide/