Mentalpositive is the operator and developer associated with the MacSync information stealer, also referred to in earlier reporting as Mac.C. Active by at least April 2025, the actor is linked to macOS-focused credential and data theft operations and appears to specialize in the comparatively smaller but profitable macOS stealer ecosystem alongside families such as AMOS and Odyssey. The actor’s tooling has been observed targeting macOS users through a signed and notarized Swift application, reflecting adaptation to Apple’s notarization and Gatekeeper controls. The malware attributed to Mentalpositive is designed to steal iCloud keychain credentials, browser passwords, system metadata, cryptocurrency wallet data, and files from the local filesystem. Reported tradecraft includes encoded payload delivery with on-host decoding, use of valid code signing and notarization to reduce user friction and bypass platform trust checks, inflation of installer disk images with decoy content, deletion of execution-chain artifacts to hinder analysis, and internet-connectivity checks prior to execution to avoid some sandboxed environments. Based on the available evidence, Mentalpositive is best characterized as a financially motivated macOS stealer actor focused on credential theft, crypto-related theft, data exfiltration, and defense evasion.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.