#ParsedReport #CompletenessMedium
08-09-2026
MacSync: The Evasive macOS Stealer Exploiting ClickFix Lures
https://www.seqrite.com/blog/macsync-the-evasive-macos-stealer-exploiting-clickfix-lures/
Report completeness: Medium
Actors/Campaigns:
Mentalpositive
Threats:
Macc_stealer
Clickfix_technique
Credential_dumping_technique
Seo_poisoning_technique
Clearfake
Lumma_stealer
Stealc
Vidar_stealer
Supply_chain_technique
Cloaking_technique
Victims:
Technology sector, Software development sector, Cryptocurrency sector, Web3 sector, Macos users
Industry:
Government, Financial, Software_development
Geo:
Canada, Australia, Germany, France, Singapore, Japan, India, Netherlands, United kingdom, United states
TTPs:
Tactics: 7
Technics: 18
IOCs:
Domain: 4
Hash: 1
Soft:
macOS, Gatekeeper, Keitaro, Zoom, Claude, ChatGPT, Docker, TradingView, curl, Telegram, have more...
Wallets:
metamask, coinbase, tronlink
Algorithms:
zip, md5, sha1, sha256, xor, base64
Functions:
fork, setsid, _Fork, _Setsid, _freopen, sub_100001e20, _system
Win API:
PIE
Languages:
python, applescript
Platforms:
apple, intel
Post #32222
42