securityonline.info 11 Sept 2026, 06:11 UTC

MacSync Stealer Targets Enterprise Macs Through Fake Verification Fixes

MacSync Stealer Targets Enterprise Macs Through Fake Verification Fixes
CyberSIXT Evidence Panel Source marked as original reporting

SECURITY researchers have detailed a macOS information stealer campaign named MacSync, which targets enterprise macOS users in tech, Web3 and government sectors. The attackers distribute a lightweight Mach-O stager via deceptive ClickFix prompts and search malvertising that lure users into copying a terminal command to fix a fake verification issue.

Running the command launches the payload in the background and bypasses Apple Gatekeeper, enabling in-memory credential harvesting without leaving obvious traces on disk. Telemetry indicates the operation operates as a malware‑as‑a‑service (MaaS) with multiple campaigns and backend infrastructures.

Infection chains begin with an initial shell script that downloads a native 64‑bit Mach‑O stager. The stager detaches from the terminal, reparents to PID 1, and redirects I/O so no output is visible. It stores server paths and commands as XOR constants, decrypting them at runtime, then streams AppleScript commands through the system script runner to prompt for passwords and dump keychains, browser data, SSH keys and cryptocurrency wallets.

The stager communicates with remote servers using custom authentication headers and chunks large exfiltrations into 10 MB slices to evade network alerts, deleting temporary archives once confirmed. A secondary remote‑access trojan may be deployed to achieve persistence via LaunchAgents. Victim concentration appears strongest in regions with dense enterprise macOS adoption, notably the United States (41.4%), with the United Kingdom (8.2%) and Germany (6.9%) also affected.

While attribution remains unconfirmed, development artefacts include Russian‑language comments and a handle “Mentalpositive.” Defenders are urged to monitor detached terminal processes, suspicious osascript activity, LaunchAgents entries, and anomalous domain traffic.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline