← Back to feed
Threat Actors & CampaignsEmerging1 sourceSep 8, 2026 · 09:55via Malware.news

MacSync: The Evasive macOS Stealer Exploiting ClickFix Lures

Brief

Executive Summary

MacSync Stealer is a family of macOS information stealers and remote-access stagers designed to evade detection and sold commercially under a malware-as-a-service (MaaS) model.

In the attack chain, MacSync binaries are native stagers and multi-part exfiltration engines. Rather than standalone harvesters, the payloads are lightweight 64-bit Mach-O executables that detach silently from terminal sessions, load credential-dumping modules directly into memory, and reliably exfiltrate stolen credentials back to campaign infrastructure.

MacSync is delivered primarily through ClickFix social engineering and search engine malvertising. It uses a modular, multi-tier execution strategy to bypass Apple Gatekeeper, XProtect, and endpoint detection and response (EDR) tools while keeping a minimal footprint on disk.

Read more on Malware.news