Find notable cyber news and cases, enriched with sources, timelines, and signals.

MacSync Stealer rotating-domain exfiltration activity

Malware Activity
First reported
Last updated
Happening score
H score 30
1 unique sources, 1 articles

Summary

Hide ▲

The MacSync Stealer operation has been tied to 30+ rotating domains and confirmed active data exfiltration, increasing the risk of credential theft on macOS endpoints. The malware uses changing infrastructure while preserving recurring network and process patterns that make the activity easier to correlate across hostnames. It targets Keychain material, browser credentials and cookies, session data, and other sensitive files. The observed workflow shows a live theft-and-upload chain rather than simple beaconing.

Related Happenings

AmnesiaStealer macOS infostealer distributed via ClickFix

Malware Activity
H score16 First: 14.08.2026 13:45 Last: 14.08.2026 13:45 Sources 1

About this happening: AmnesiaStealer is a Rust-based macOS infostealer spread through a counterfeit GitHub "Download for macOS" page and ClickFix-style lure. It steals Keychain, b...

Go-based macOS stealer with DRAIN wallet-draining routine

Malware Activity
H score29 First: 07.08.2026 21:29 Last: 07.08.2026 21:29 Sources 1

About this happening: A Go-based macOS stealer delivered through ClickFix-style attacks is stealing browser passwords, Apple iCloud Keychain data, and cached credentials while also...

ClickFix Go-based macOS infostealer and crypto drainer

Malware Activity
H score29 First: 07.08.2026 01:37 Last: 07.08.2026 01:37 Sources 1

About this happening: A Go-based malware delivered through ClickFix is targeting macOS users to steal cryptocurrency assets, browser-stored passwords, Apple iCloud Keychain data...

ClickFix macOS Terminal-command lure campaign

Campaign
H score42 First: 07.08.2026 01:37 Last: 07.08.2026 01:37 Sources 1

About this happening: The ClickFix campaign is delivering a Go-based macOS stealer through Terminal commands pasted from lure pages, creating a path to browser password theft, Apple K...

ClickLock Stealer macOS forced-interaction infostealer activity

Malware Activity
H score27 First: 16.07.2026 15:33 Last: 16.07.2026 15:33 Sources 1

About this happening: ClickLock Stealer is a macOS information-stealing malware that uses a ClickFix-style paste into Terminal and a fake system dialog to coerce users into entering the...

Timeline

  1. 19.08.2026 09:01 2 articles · 5h ago

    Microsoft links 30+ domains to MacSync Stealer infrastructure

    Initial Disclosure

    Microsoft Defender Experts linked more than 30 web domains to MacSync Stealer on 2026-08-19 after correlating recurring endpoint and network behavior across changing infrastructure, including an interactive zsh Terminal session consistent with ClickFix social engineering, curl retrieval over /curl/, AppleScript-assisted execution via osascript, staging under /tmp/sync*, and HTTP PUT uploads of /tmp/osalogging.zip with chunk-management parameters. Microsoft also said the investigation confirmed active data exfiltration rather than beaconing.

    Show sources