MacSync is a macOS information-stealing malware family used in multi-stage social-engineering campaigns. It has been observed in ClickFix-style and malvertising-driven delivery chains that trick victims into pasting malicious commands into Terminal, including lures themed as software installation help and counterfeit download pages. The malware is associated with campaigns that rely on user execution rather than software exploitation and has also appeared alongside shared lure infrastructure used to distribute other macOS stealers such as Atomic Stealer (AMOS).
MacSync is designed to steal browser cookies and saved logins, keychain secrets, cloud and developer credentials, SSH material, Telegram session data, and cryptocurrency wallet-related information. Reported campaigns show repeated prompting for the victim’s macOS password using fake native authentication dialogs, attempts to obtain elevated access such as Full Disk Access, and staging of collected data for exfiltration. MacSync has also been described as combining credential theft with longer-term post-compromise access.
Beyond data theft, MacSync can install a persistent remote-access component on infected Macs. That component has been reported to support command execution, file transfer, and screen capture, extending the intrusion beyond simple collection into active operator control. Persistence has been observed through macOS launch mechanisms.
A notable focus of MacSync operations is cryptocurrency theft. The malware searches for numerous wallet browser extensions and desktop wallet applications, and some campaigns have replaced wallet companion applications with trojanized versions that present fraudulent recovery workflows to steal seed phrases. This combination of infostealing, remote access, screen capture, and wallet-focused phishing makes MacSync a broader macOS intrusion platform rather than a narrow browser stealer.
MacSync targets macOS users and has been observed in campaigns aimed at individuals seeking popular software or AI tooling, using deceptive branding, sponsored search placement, and fake support or download content to drive execution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
"Threat Details and IOCs Malware: Mac.c, MacSync, MacSync Stealer CVEs: CVE-2023-31290"
28 distinct techniques documented for this family, organized by ATT&CK tactic.
File artifact ~/Library/LaunchAgents/com.apple.[8hex].hcpi.plist LaunchAgent persistence
When the victim runs the Terminal command, the campaign retrieves and executes a remote script from a /curl/<id> URL.
The loader called a remote AppleScript directly into memory, reducing evidence on the device.
Earlier pages exposed the ClickFix instructions, clipboard logic, obfuscated shell command, and encoded staging address directly in their HTML, making them easy for static scanners to recover.
The page uses GitHub-themed branding to mimic a legitimate software download experience; the branding is spoofed and does not indicate any compromise of GitHub.
The malware packaged the information for upload before removing temporary files.
The server-side gate hides the malicious page from crawlers and sandboxes while presenting selected Mac users with a fake software download.
The gate's script, about 2.5 KB of JavaScript, reads navigator values such as the platform string, which should report MacIntel on a real Mac, along with screen and window dimensions and WebGL graphics signals that help separate genuine Apple hardware from a virtual machine or an emulated environment. It checks the timezone, whether the page is boxed inside an iframe, and whether the device reports touch support, which desktop Macs generally do not.
Once access was granted, the AppleScript displayed a false system prompt and repeatedly requested the macOS account password until it validated.
MacSync collects saved logins, cookies, keychain data, Telegram sessions, SSH and cloud credentials.
The result can be stolen browser sessions... It harvested browser cookies and saved logins.
The server-side gate hides the malicious page from crawlers and sandboxes while presenting selected Mac users with a fake software download.
The gate's script, about 2.5 KB of JavaScript, reads navigator values such as the platform string, which should report MacIntel on a real Mac, along with screen and window dimensions and WebGL graphics signals that help separate genuine Apple hardware from a virtual machine or an emulated environment. It checks the timezone, whether the page is boxed inside an iframe, and whether the device reports touch support, which desktop Macs generally do not.
Once access was granted, the AppleScript displayed a false system prompt and repeatedly requested the macOS account password until it validated.
259 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
103 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Previously seen macOS infostealer referenced because the same distribution template was used to spread it.
Referenced as a similar macOS stealer for comparison only.
Referenced as another macOS infostealer with overlapping objectives for comparison to AmnesiaStealer.
Mentioned for comparison as another stealer with similar objectives.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.