s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-osx.macsync

📛 Threat Title

Malware family: MacSync

Category: MacSync First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `osx.macsync`. Printable name: MacSync.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:bazaar.abuse.ch

    A malware sample can be associated with only one malware family . The page below gives you an overview on malware samples that MalwareBazaar has identified as MacSync .

  • web:cyberpress.org

    A phishing campaign mimicking Microsoft logins at crosoftonline [.]com/login.srf, redirecting to macclouddrive [.]com/s2/, a ClickFix lure disguised as macOS cloud storage. Victims are tricked into pasting a Terminal command, evading Gatekeeper and deploying MacSync a budget Malware -as-a-Service (MaaS) infostealer evolved from Mac.c, first seen April 2025 and rebranded by "mentalpositive ...

  • web:malpedia.caad.fkie.fraunhofer.de

    According to Zscaler, MacSync (also tracked as MacSync Stealer) is a macOS information stealer likely developed by a Russian-speaking threat actor, as evidenced by Russian-language comments found in its third-stage AppleScript payload. It is distributed through a multi-stage ClickFix campaign that abuses shared Claude chats, ultimately delivering the core stealer via osascript, which leaves no ...

  • web:redpiranha.net

    A sophisticated macOS infostealer campaign is actively targeting government and enterprise endpoints. MacSync Stealer; distributed as a Malware -as-a-Service (MaaS) operation, has evolved through three distinct campaigns since November 2025, each iteration demonstrating deliberate adaptation to macOS security controls.

  • web:samurai.by.security.ntt

    MacSync is an emerging macOS infostealer that has evolved to bypass Apple security controls through signed and notarized Swift applications. This report outlines recent MacSync activity, including delivery methods, command‑and‑control patterns, and detection logic, and highlights how these behaviors can be identified and mitigated through threat hunting and network‑based detection.

  • web:thehackernews.com

    A new MacSync macOS stealer spreads via a signed, notarized fake installer, bypassing Apple Gatekeeper before Apple revoked the certificate.

  • web:thehackernews.com

    ClickFix campaigns spread MacSync macOS infostealer via malicious Terminal commands since Nov 2025, targeting AI tool users and developers.

  • web:www.jamf.com

    Jamf Threat Labs discovers MacSync Stealer's evolution to code-signed, notarized Swift applications that silently download and execute payloads, bypassing traditional macOS security measures.

  • web:www.microsoft.com

    These reports provide the intelligence, protection information, and recommended actions to help prevent, mitigate, or respond to associated threats found in customer environments. Microsoft Defender threat analytics From ClickFix to code signed: the quiet shift of MacSync Stealer malware .

  • web:www.pcrisk.com

    MacSync malware overview The known MacSync infections originated from ClickFix scams that tricked victims into executing a malicious command on their devices, thus triggering the malware download/installation. Upon successful infiltration, MacSync displays a fake prompt requesting users to provide the device password.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.