CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

MacSync

malware · malware:macsync single-source

Six-stage macOS infostealer and remote-access tool analysed by Huntress, delivered through a sponsored search result leading to a publicly shared conversation page on the genuine claude.ai domain that instructs the victim to paste a curl one-liner into Terminal. Stages run a polymorphic zsh loader in memory, a server-side AppleScript stealer, a Mach-O remote-access tool persisting via a launch agent, a helper for the screen-recording permission and a set of wallet-application trojans; collection covers browser cookies and logins, keychain secrets, Telegram sessions, SSH and cloud keys (Huntress, 2026-08-17).

Coverage
2
0 about it · 2 mentions · first 2026-07-14 → last 2026-08-07
Latest activity
–
no entry about it yet
Peak priority
·
no entry about it yet
Targets
·
no sector or region stated
Sources cited
3
3 hosts

Story timeline

Every entry that names MacSync, newest first. Rows tagged mention only name it in passing: they are listed for completeness and add nothing to the action items, pivots or ATT&CK profile on this page.

  1. 2026-08-07The macOS ClickFix chain now qualifies visitors server-side before showing the lure, with anti-analysis probes that detect a console rather than a sandbox
    mentionactive-threatsMicrosoft documents the cloaking layer in front of a ClickFix campaign, researchers and scanners get a decoy, qualified Macs get the payload
  2. 2026-07-14CrashStealer, a native-C++ macOS infostealer using a notarized dropper and local dscl password validation to raid keychain, browsers and wallets
    mentionactive-threatsCrashStealer: notarized-dropper macOS stealer validates stolen passwords with dscl before harvesting keychain and browser data

Entries about MacSync

No published entry is about this entity yet · the story timeline above lists the entries that mention it.

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Threats2

Source distribution

  • bleepingcomputer.com1 (33%)
  • jamf.com1 (33%)
  • microsoft.com1 (33%)