MacSync Stealer rotating-domain exfiltration activity
Malware Activity
Summary
Hide ▲
Show ▼
The MacSync Stealer operation has been tied to 30+ rotating domains and confirmed active data exfiltration, increasing the risk of credential theft on macOS endpoints. The malware uses changing infrastructure while preserving recurring network and process patterns that make the activity easier to correlate across hostnames. It targets Keychain material, browser credentials and cookies, session data, and other sensitive files. The observed workflow shows a live theft-and-upload chain rather than simple beaconing.
Related Happenings
AmnesiaStealer macOS infostealer distributed via ClickFix
Malware Activity
H score16
First: 14.08.2026 13:45
Last: 14.08.2026 13:45
Sources 1
About this happening:
AmnesiaStealer is a Rust-based macOS infostealer spread through a counterfeit GitHub "Download for macOS" page and ClickFix-style lure. It steals Keychain, b...
AmnesiaStealer macOS infostealer distributed via ClickFix
Malware ActivityAbout this happening: AmnesiaStealer is a Rust-based macOS infostealer spread through a counterfeit GitHub "Download for macOS" page and ClickFix-style lure. It steals Keychain, b...
Go-based macOS stealer with DRAIN wallet-draining routine
Malware Activity
H score29
First: 07.08.2026 21:29
Last: 07.08.2026 21:29
Sources 1
About this happening:
A Go-based macOS stealer delivered through ClickFix-style attacks is stealing browser passwords, Apple iCloud Keychain data, and cached credentials while also...
Go-based macOS stealer with DRAIN wallet-draining routine
Malware ActivityAbout this happening: A Go-based macOS stealer delivered through ClickFix-style attacks is stealing browser passwords, Apple iCloud Keychain data, and cached credentials while also...
ClickFix Go-based macOS infostealer and crypto drainer
Malware Activity
H score29
First: 07.08.2026 01:37
Last: 07.08.2026 01:37
Sources 1
About this happening:
A Go-based malware delivered through ClickFix is targeting macOS users to steal cryptocurrency assets, browser-stored passwords, Apple iCloud Keychain data...
ClickFix Go-based macOS infostealer and crypto drainer
Malware ActivityAbout this happening: A Go-based malware delivered through ClickFix is targeting macOS users to steal cryptocurrency assets, browser-stored passwords, Apple iCloud Keychain data...
ClickFix macOS Terminal-command lure campaign
Campaign
H score42
First: 07.08.2026 01:37
Last: 07.08.2026 01:37
Sources 1
About this happening:
The ClickFix campaign is delivering a Go-based macOS stealer through Terminal commands pasted from lure pages, creating a path to browser password theft, Apple K...
ClickFix macOS Terminal-command lure campaign
CampaignAbout this happening: The ClickFix campaign is delivering a Go-based macOS stealer through Terminal commands pasted from lure pages, creating a path to browser password theft, Apple K...
ClickLock Stealer macOS forced-interaction infostealer activity
Malware Activity
H score27
First: 16.07.2026 15:33
Last: 16.07.2026 15:33
Sources 1
About this happening:
ClickLock Stealer is a macOS information-stealing malware that uses a ClickFix-style paste into Terminal and a fake system dialog to coerce users into entering the...
ClickLock Stealer macOS forced-interaction infostealer activity
Malware ActivityAbout this happening: ClickLock Stealer is a macOS information-stealing malware that uses a ClickFix-style paste into Terminal and a fake system dialog to coerce users into entering the...
Timeline
-
19.08.2026 09:01 2 articles · 5h ago
Microsoft links 30+ domains to MacSync Stealer infrastructure
Initial DisclosureMicrosoft Defender Experts linked more than 30 web domains to MacSync Stealer on 2026-08-19 after correlating recurring endpoint and network behavior across changing infrastructure, including an interactive zsh Terminal session consistent with ClickFix social engineering, curl retrieval over /curl/, AppleScript-assisted execution via osascript, staging under /tmp/sync*, and HTTP PUT uploads of /tmp/osalogging.zip with chunk-management parameters. Microsoft also said the investigation confirmed active data exfiltration rather than beaconing.
Show sources
- Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure — thehackernews.com — 19.08.2026 09:01
- Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure — thehackernews.com — 19.08.2026 09:01