Sunday, September 13, 2026

MacSync macOS Infostealer Exploits ClickFix-style Attack to Trick Users with Single Terminal Command

A sophisticated macOS infostealer campaign that leverages deceptive ClickFix-style social engineering to distribute MacSync, a Malware-as-a-Service (MaaS) credential-stealing tool targeting cryptocurrency users.

The attack chain begins with phishing redirects and culminates in persistent access through trojanized hardware wallet applications.

The campaign initiates with credential harvesters impersonating Microsoft login pages. Analysis of crosoftonline[.]com/login[.]srf a domain spoofing official Microsoft authentication revealed HTTP redirect chains leading to macclouddrive[.]com/s2/, a convincingly designed macOS cloud storage installer page.

The lure page presents a single Terminal command under the guise of “advanced installation,” complete with fake App Store echoes and a prominent copy button.

A dedicated “Terminal installation” section targets “advanced users,” presenting a single command as a convenient alternative to traditional downloads.

Delivery Method (Source : CloudSEK).
Delivery Method (Source : CloudSEK).

The payload string decodes to fetch code from jmpbowl[.]xyz, triggering a multi-stage infection that ultimately compromises browser credentials, cryptocurrency wallets, and system Keychain data.

Multi-Stage Infection Chain

Stage One: Initial Payload

The one-liner command pipes a base64-encoded URL directly to Zsh, bypassing Gatekeeper and notarization entirely. Upon execution, it downloads a lightweight daemonized Zsh loader that immediately backgrounds itself, severing Terminal visibility.

Stage Two: Dynamic Payload Delivery

The stager fetches an AppleScript core payload from /dynamic endpoints using unique build tokens tied to victim tracking. The stager redirects all output to /dev/null, ensuring silent execution while maintaining C2 connectivity through hardcoded API keys.

The Remote AppleScript Infostealer (Source : CloudSEK).

Stage Three: Data Exfiltration

The AppleScript module performs systematic harvesting of:

  • Browser profiles across Chromium derivatives (Chrome, Brave, Edge, Arc, Vivaldi, Opera, Yandex)
  • 25+ cryptocurrency wallet extension IDs, targeting MetaMask, Phantom, Binance Wallet, Coinbase Wallet, and others
  • Desktop wallet applications (Exodus, Electrum, Atomic, Wasabi, Bitcoin Core, Guarda)
  • Complete Keychain databases containing Wi-Fi, application, and SSH credentials
  • SSH keys, AWS credentials, and Kubernetes configurations
  • Telegram session data and Apple Notes databases
  • Opportunistic files from Desktop, Documents, and Downloads

Critically, the script implements persistent phishing dialogs mimicking “System Preferences” with Russian-language labels, repeatedly prompting for the macOS login password. This credential is saved in plaintext for offline decryption of encrypted browser and Keychain data.

Persistence Through Trojanization

MacSync addressed a significant escalation in macOS malware sophistication, combining effective social engineering, multi-stage evasion, comprehensive data harvesting, and post-compromise persistence.

MacSync elevates select infections through conditional application trojanization. When Ledger Wallet.app or Trezor Suite.app are detected in /Applications/, the payload downloads malicious bundles and performs partial or complete replacement.

For Ledger, only app.asar and Info.plist are overwritten, preserving legitimate app resources and minimizing detection. The new bundle applies ad-hoc code signing, bypassing standard Gatekeeper validation.

For Trezor Suite, the entire application bundle is replaced. Both variants inject a convincing multi-step phishing wizard presenting error recovery screens followed by PIN and recovery phrase collection forms, capturing credentials under the guise of firmware fixes.

The focus on cryptocurrency users and hardware wallet applications demonstrates clear understanding of high-value targets within the macOS ecosystem.

At least eight rotating C2 domains follow consistent naming patterns (jmpbowl[.]xyz variants).

Multiple /v1-/v3 paths and five near-identical clone sites indicate ongoing campaign evolution. Each build receives unique tokens enabling precise victim tracking and payload customization.

The absence of traditional binary artifacts relying instead on script-based execution severely complicates detection, while conditional trojanization ensures long-term access only on systems containing valuable applications.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Threat Actors Use Claude AI Agents to Automate Cyberattacks and Steal Sensitive Data

Threat actors are increasingly using Claude-based AI workflows to...

China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks

China-linked threat actors UTA0560 and JungleBamboo chained a Google...

New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets

A newly identified phishing campaign is abusing the legitimate...

CISA Warns of Critical GitLab Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

Related Articles

Recent News