MacSync Stealer is a macOS-exclusive, multi-stage information stealer distributed through ClickFix social engineering. Campaigns have used sponsored search advertisements and counterfeit support or software-installation guidance hosted on trusted services to persuade victims to paste malicious curl commands into Terminal. The resulting shell-based execution chain uses native macOS utilities and AppleScript to retrieve, decode, and launch payloads.
MacSync collects macOS Keychain secrets; browser credentials, cookies, session data, and browser storage; Apple Notes and Safari data; SSH keys; cloud credentials, including AWS credentials and Kubernetes configurations; Telegram sessions; sensitive user documents; and cryptocurrency wallet artifacts. It targets wallet applications, browser extensions, and hardware-wallet companion software, and can modify selected wallet applications to present fraudulent recovery-phrase prompts. Collected information is staged, compressed, split into chunks, and exfiltrated through HTTP PUT requests before local temporary artifacts are removed.
Reported MacSync deployments also include a persistent remote-access component installed through a LaunchAgent. This component provides operators with an interactive shell, command execution in the victim user context, and file transfer capability. Other components seek Full Disk Access and Screen Recording permissions, enabling broader collection and display capture when the victim grants consent. The malware uses rotating delivery and command-and-control infrastructure, while retaining recurring execution and exfiltration behaviors. No specific threat actor attribution is established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
"Threat Details and IOCs Malware: Mac.c, MacSync, MacSync Stealer CVEs: CVE-2023-31290"
36 distinct techniques documented for this family, organized by ATT&CK tactic.
The payload uses osascript for AppleScript-assisted execution alongside native macOS and Unix utilities
“The ‘Apple Support install guide’ told the victim to paste a curl command into Terminal.”
The researchers said the loader changes for each victim, making simple file-hash blocking unreliable. Defenders should instead watch for unusual curl activity, encoded Base64 content in shell commands
“The artifact visually impersonated a Claude Desktop / Claude Cowork download page” and the “claude.ai/share conversation [was] posing as an Apple Support guide.”
The malware removes temporary archives, staging folders, lock files, and other artifacts after exfiltration
The malicious code looks for ... AWS credentials, Kubernetes configurations
“MacSync stealer ... resulted in the comprehensive theft of cookies.”
Collecte de données : ... clés SSH, credentials AWS, configurations Kubernetes ... fichiers sensibles ...
“MacSync stealer ... resulted in the comprehensive theft of ... SSH and cloud keys.”
“This launched a six-stage kill chain for the MacSync stealer that resulted in the comprehensive theft of cookies, credentials, keychain secrets, Telegram sessions, SSH and cloud keys.”
Collecte de données : ... clés SSH, credentials AWS, configurations Kubernetes, Apple Notes, données Safari, fichiers sensibles (PDF, DOCX, TXT, KEY, PEM, KDBX, OVPN, WALLET, SEED), wallets crypto (Ledger, Trezor)
A separate signed helper seeks Screen Recording permission, allowing the attackers to capture the victim’s display after consent is granted.
Exfiltration : upload via curl HTTP PUT avec --data-binary , headers api-key , User-Agent macOS, paramètres upload_id , chunk_index , total_chunks sur chemin /gate?buildtxd=
285 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
112 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
macOS-focused information stealer that steals cookies, credentials, keychain secrets, Telegram sessions, SSH keys, and cloud keys.
Referenced as another macOS stealer used for comparison with AmnesiaStealer.
A macOS stealer targeting credentials, payment card data, keychain details, and cryptocurrency wallets.
macOS infostealer that uses ClickFix-style social engineering to trick users into pasting and executing a zsh command, then downloads a payload via curl, uses AppleScript-assisted execution, collects credentials and sensitive files from browsers, Keychain, SSH, AWS, Kubernetes, Notes, Safari, and crypto wallets, stages and compresses the data, and exfiltrates it over HTTP PUT to attacker-controlled C2 infrastructure before cleaning up artifacts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.