MacSync Stealer is a macOS information-stealing malware family active since late 2025 and increasingly associated with ClickFix-style social engineering campaigns. It is commonly delivered by luring users into manually pasting obfuscated shell commands into Terminal, including campaigns that abused Google Ads, Claude shared chats, fake utility or troubleshooting pages, and other trusted-looking developer or AI-themed lures. Earlier reporting also links its distribution to SEO poisoning and fake cracked-software ecosystems, indicating flexible criminal delivery infrastructure.
The malware is designed to harvest a broad range of sensitive data from macOS systems. Confirmed collection targets include browser credentials, cookies, saved logins, Keychain material, Chrome Safe Storage-related secrets, SSH keys, cloud and developer credentials such as AWS and Kubernetes configuration data, Telegram Desktop data, shell history, selected user documents, password-manager extension data, and cryptocurrency wallet data from both browser extensions and desktop wallet applications. Multiple reports also describe targeted abuse of hardware-wallet ecosystems, including trojanization of Ledger-related applications and targeting of Trezor software to steal wallet secrets or recovery material.
MacSync commonly uses AppleScript as a core execution and collection component and has been observed presenting fake macOS system prompts to steal the victim’s login password. In documented campaigns, entered passwords were validated locally with native macOS mechanisms before further collection activity, enabling access to protected stores such as the login keychain. Some variants also prompt for Full Disk Access and, when initial access to protected data fails, establish user-level persistence by modifying shell startup behavior so the malware re-executes when Terminal is opened. Other observed tradecraft includes output suppression, in-memory or pipe-based staging, compression of stolen data, chunked exfiltration, cleanup of temporary artifacts, and deletion of evidence after theft.
MacSync is part of the broader expansion of commodity infostealer activity from Windows into macOS. It has been observed alongside other macOS stealers such as AMOS, SHub Stealer, Odyssey, Phexia, and DigitStealer in overlapping ClickFix and malvertising ecosystems. Some reporting notes Russian-language comments in AppleScript payloads, suggesting likely Russian-speaking operators, while other observations describe CIS-region avoidance checks in related MacSync-linked campaigns. The malware has been repeatedly associated with targeting cryptocurrency users, developers, and users seeking AI or developer tooling, making it relevant to both consumer theft and enterprise credential-compromise risk.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
"Threat Details and IOCs Malware: Mac.c, MacSync, MacSync Stealer CVEs: CVE-2023-31290"
24 distinct techniques documented for this family, organized by ATT&CK tactic.
The chat instructs victims to copy and paste a Base64-obfuscated curl command into Terminal
Once fully deployed via AppleScript, MacSync Stealer tricks victims into entering their macOS password through a fake system prompt... Analysts found Russian-language code comments inside the malware’s AppleScript payload...
The chat instructs victims to copy and paste a Base64-obfuscated curl command into Terminal
The chat is labeled “Shared by Apple Support” in the top right corner. The threat actors likely achieved this by setting their Claude display name as “Apple Support”
MacSync Stealer tricks victims into entering their macOS password through a fake system prompt...
MacSync Stealer tricks victims into entering their macOS password through a fake system prompt
SSH keys, AWS credentials, and Kubernetes configs from developer environments
Keychain files and credentials from Chromium and Gecko-based browsers, including cookies and saved logins
Telegram Desktop files, documents, and files with extensions like .pdf, .wallet, and .kdbx Cryptocurrency wallet browser extensions and desktop wallet applications
MacSync Stealer tricks victims into entering their macOS password through a fake system prompt...
196 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
78 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as another macOS malware family observed in related ClickFix campaigns.
A macOS stealer referenced for comparison in ClickFix distribution infrastructure analysis.
A macOS information stealer delivered via ClickFix-style social engineering using malicious Google Ads and abused Claude shared chats. It uses AppleScript, prompts victims for their macOS password via a fake system prompt, steals Keychain data, browser credentials and cookies, password manager extension data, SSH keys, AWS credentials, Kubernetes configs, Telegram files, documents, and cryptocurrency wallet data, then compresses and exfiltrates the data and deletes traces from the system.
A macOS information stealer delivered via a ClickFix-style social engineering chain abusing Claude shared chats and Google Ads. It uses Base64-obfuscated curl commands, AppleScript, fake system prompts to capture the macOS password, steals credentials, browser data, Keychain files, SSH keys, AWS credentials, Kubernetes configs, Telegram files, documents, and cryptocurrency wallet data, then compresses and exfiltrates the data before deleting traces from the system.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.