MacSync Malware Steals Credentials and Cryptocurrency Wallet Data from Apple Users
A new malware campaign targeting Apple users has been discovered, using social engineering tactics to steal credentials and cryptocurrency wallet data. The malware, called MacSync, is a macOS-focused information stealer that operates through ClickFix lures, search-engine malvertising, and fake software download pages.
The attackers impersonate popular brands such as Google Meet, Zoom, Claude AI, ChatGPT, Cloudflare, Docker, Notion, Cursor, TradingView, and cryptocurrency applications to trick victims into running a command in the macOS Terminal. Once executed, the command launches a lightweight native Mach-O stager that silently detaches from the Terminal session.
The MacSync samples use single-byte XOR obfuscation with the 0xAA key to hide command strings, temporary paths, API headers, and C2 addresses from static security scans. The attackers then download a dynamic AppleScript payload over HTTPS, which collects sensitive data including browser credentials, cookies, macOS Keychain data, SSH keys, Telegram sessions, cloud tokens, environment files, and cryptocurrency wallet databases.