MacSync macOS Infostealer Leverage ClickFix-style Attack to Trick Users Pasting a Single Terminal Command
The MacSync malware presents a significant risk to macOS users, particularly those involved in cryptocurrency transactions, through advanced social engineering techniques.
The MacSync malware presents a significant risk to macOS users, particularly those involved in cryptocurrency transactions, through advanced social engineering techniques.
MacSync functions as a Malware-as-a-Service (MaaS) targeting macOS systems. It prompts users to execute a single Terminal command, leading to data extraction. Initially discovered during an investigation into phishing schemes, MacSync utilizes fake cloud storage installer pages to guide victims through malicious installation steps.
The malware is an evolution of the Mac.c stealer, valued for its cost-effectiveness and modular design tailored for cryptocurrency data theft.
MacSync exploits user trust in standard macOS workflows. A deceptive landing page mimics legitimate software interfaces, complete with a "Verified Publisher" badge. A clipboard command initiates the breach, circumventing macOS security measures like Gatekeeper.
MacSync functions as a Malware-as-a-Service (MaaS) targeting macOS systems.
The infection chain, analyzed by CloudSEK, operates through scripts, beginning with a Zsh loader that executes in the background. This loader retrieves a remote AppleScript payload to perform data theft.
MacSync focuses on extracting cryptocurrency-related information. It prompts users for login credentials via fake system dialogs, effectively capturing sensitive data. Browser profiles, including saved passwords and authentication cookies, are systematically collected from various Chromium-based browsers.
The malware targets cryptocurrency wallet extensions to obtain seed phrases and private keys. Additionally, it accesses SSH keys, AWS credentials, Keychain databases, and Apple Notes.
MacSync can also compromise hardware wallet applications, such as Ledger and Trezor, by replacing legitimate software with malicious versions to capture sensitive information over time.
The malware's infrastructure involves multiple rotating command-and-control (C2) domains and variant lure pages, indicating ongoing campaign adaptations. This modular design showcases MacSync as a scalable and persistent threat within the macOS cryptocurrency community.
Based on reporting by Cyber Security News.
