MacSync is a multi-stage macOS information stealer with remote-access functionality that targets credentials, browser data, cryptocurrency assets, and other sensitive user material. It has been observed in socially engineered infection chains that trick victims into pasting malicious commands into Terminal, including ClickFix-style lures and malvertising-driven fake software installation guidance. Delivery tradecraft has included spoofed support content and GitHub-themed download pages used to persuade users to self-execute the initial loader.
MacSync has been described as a six-component chain that begins with a shell-based loader and progresses through in-memory execution of an AppleScript stealer, installation of a persistent native Mach-O remote-access component, abuse of macOS privacy permissions, and deployment of trojanized cryptocurrency wallet applications. The malware steals browser cookies and saved logins, keychain secrets, account passwords, Telegram sessions, SSH keys, cloud-related credentials, and other developer or authentication material. It also validates captured macOS account passwords and uses them to unlock protected data sources.
Beyond credential theft, MacSync establishes persistence through user-login mechanisms and provides post-compromise remote control. Its RAT functionality supports command execution, interactive shell access, file upload and download, and screen capture. The malware has also been observed prompting for or abusing Full Disk Access and Screen Recording permissions to expand collection from protected macOS data stores.
A notable feature is its strong focus on cryptocurrency theft. MacSync searches for numerous wallet browser extensions and desktop wallet applications and can replace selected wallet companion applications with trojanized versions that present fake recovery workflows to steal seed phrases. This combines conventional infostealing with wallet-focused phishing and longer-term access to digital assets.
MacSync overlaps in objectives with other macOS stealers such as Atomic Stealer and CrashStealer, but is distinguished by its staged architecture combining infostealing, persistence, remote administration, screen capture, and wallet-app trojanization on macOS systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
"Threat Details and IOCs Malware: Mac.c, MacSync, MacSync Stealer CVEs: CVE-2023-31290"
28 distinct techniques documented for this family, organized by ATT&CK tactic.
When the victim runs the Terminal command, the campaign retrieves and executes a remote script from a /curl/<id> URL.
This loader is a three-line wrapper around a gzip-compressed, Base64-encoded payload delivered as a heredoc.
The page uses GitHub-themed branding to mimic a legitimate software download experience; the branding is spoofed and does not indicate any compromise of GitHub.
The malware packaged the information for upload before removing temporary files.
an AppleScript payload ( osascript ) that runs fully in system memory
The server-side gate hides the malicious page from crawlers and sandboxes while presenting selected Mac users with a fake software download.
The gate's script, about 2.5 KB of JavaScript, reads navigator values such as the platform string, which should report MacIntel on a real Mac, along with screen and window dimensions and WebGL graphics signals that help separate genuine Apple hardware from a virtual machine or an emulated environment. It checks the timezone, whether the page is boxed inside an iframe, and whether the device reports touch support, which desktop Macs generally do not.
MacSync collects browser cookies and logins, keychain secrets, account passwords
MacSync collects saved logins, cookies, keychain data, Telegram sessions, SSH and cloud credentials.
the osascript pulls every browser's Chromium "Safe Storage" AES key out of the login keychain and extracts every Safe Storage password
The server-side gate hides the malicious page from crawlers and sandboxes while presenting selected Mac users with a fake software download.
The gate's script, about 2.5 KB of JavaScript, reads navigator values such as the platform string, which should report MacIntel on a real Mac, along with screen and window dimensions and WebGL graphics signals that help separate genuine Apple hardware from a virtual machine or an emulated environment. It checks the timezone, whether the page is boxed inside an iframe, and whether the device reports touch support, which desktop Macs generally do not.
259 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
104 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A macOS infostealer with a multi-stage kill chain that uses a zsh loader, in-memory AppleScript theft, a persistent Mach-O RAT, a helper to obtain Screen Recording TCC permission, and trojanized wallet applications to steal credentials, sessions, keys, and cryptocurrency recovery phrases.
Previously seen macOS infostealer referenced because the same distribution template was used to spread it.
Referenced as a similar macOS stealer for comparison only.
Referenced as another macOS infostealer with overlapping objectives for comparison to AmnesiaStealer.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.