TF-MAL-osx.macsync
📛 Threat Title
Malware family: MacSync
Description
ThreatFox malware family `osx.macsync`. Printable name: MacSync.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:bazaar.abuse.ch
A malware sample can be associated with only one malware family . The page below gives you an overview on malware samples that MalwareBazaar has identified as MacSync .
-
web:cyberpress.org
A phishing campaign mimicking Microsoft logins at crosoftonline [.]com/login.srf, redirecting to macclouddrive [.]com/s2/, a ClickFix lure disguised as macOS cloud storage. Victims are tricked into pasting a Terminal command, evading Gatekeeper and deploying MacSync a budget Malware -as-a-Service (MaaS) infostealer evolved from Mac.c, first seen April 2025 and rebranded by "mentalpositive ...
-
web:malpedia.caad.fkie.fraunhofer.de
According to Zscaler, MacSync (also tracked as MacSync Stealer) is a macOS information stealer likely developed by a Russian-speaking threat actor, as evidenced by Russian-language comments found in its third-stage AppleScript payload. It is distributed through a multi-stage ClickFix campaign that abuses shared Claude chats, ultimately delivering the core stealer via osascript, which leaves no ...
-
web:redpiranha.net
A sophisticated macOS infostealer campaign is actively targeting government and enterprise endpoints. MacSync Stealer; distributed as a Malware -as-a-Service (MaaS) operation, has evolved through three distinct campaigns since November 2025, each iteration demonstrating deliberate adaptation to macOS security controls.
-
web:samurai.by.security.ntt
MacSync is an emerging macOS infostealer that has evolved to bypass Apple security controls through signed and notarized Swift applications. This report outlines recent MacSync activity, including delivery methods, command‑and‑control patterns, and detection logic, and highlights how these behaviors can be identified and mitigated through threat hunting and network‑based detection.
-
web:thehackernews.com
A new MacSync macOS stealer spreads via a signed, notarized fake installer, bypassing Apple Gatekeeper before Apple revoked the certificate.
-
web:thehackernews.com
ClickFix campaigns spread MacSync macOS infostealer via malicious Terminal commands since Nov 2025, targeting AI tool users and developers.
-
web:www.jamf.com
Jamf Threat Labs discovers MacSync Stealer's evolution to code-signed, notarized Swift applications that silently download and execute payloads, bypassing traditional macOS security measures.
-
web:www.microsoft.com
These reports provide the intelligence, protection information, and recommended actions to help prevent, mitigate, or respond to associated threats found in customer environments. Microsoft Defender threat analytics From ClickFix to code signed: the quiet shift of MacSync Stealer malware .
-
web:www.pcrisk.com
MacSync malware overview The known MacSync infections originated from ClickFix scams that tricked victims into executing a malicious command on their devices, thus triggering the malware download/installation. Upon successful infiltration, MacSync displays a fake prompt requesting users to provide the device password.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.