ZeroHour
Story · 2 sources · 2 articlesfirst updated ()

ClickFix Lures Deliver MacSync macOS Infostealer Through Fake Claude, ChatGPT, Zoom, and Docker Installers

mediumMalwareexploited in the wildimportance 58
What's new: First merged summary for this story; no previous dashboard summary existed. This entry consolidates same-day (2026-09-10) coverage from GBHackers and Cyber Security News (citing SEQRITE). No direct factual conflicts were found; noted wording differences: LaunchAgents described as 'fake/masquerading' (GBHackers) vs 'renamed' (Cyber Security News), and stolen session data described as 'session…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Threat actors are distributing MacSync, a macOS infostealer sold as malware-as-a-service, via ClickFix social-engineering lures, malvertising, SEO poisoning, and sponsored search ads impersonating Claude, ChatGPT, Zoom, and Docker. Victims paste curl-to-zsh…

Per 2026-09-10 reports from GBHackers and Cyber Security News (citing SEQRITE), a malware-as-a-service campaign pushes MacSync, a macOS infostealer, through ClickFix social-engineering lures, malvertising, SEO poisoning, and sponsored search ads impersonating brands including Claude, ChatGPT, Zoom, and Docker. Victims are tricked into manually pasting curl-to-zsh commands into Terminal, sidestepping Gatekeeper and notarization checks. The resulting stager is a 64-bit Mach-O binary with single-byte XOR string obfuscation that daemonizes, polls its C2 server with custom API-key headers, and streams AppleScript payloads into osascript for in-memory execution. MacSync (formerly Mac.c, emerged April 2025, linked to developer 'Mentalpositive') harvests browser credentials and vaults, Keychain data, SSH keys, session tokens/cookies, messaging sessions, and cryptocurrency wallets, then exfiltrates staged archives in 10MB HTTP PUT chunks. It persists via LaunchAgents (described as fake/masquerading by GBHackers and renamed by Cyber Security News) and can request screen-recording permissions. GBHackers, citing Microsoft, reports more than 30 related MacSync domains identified through behavioral pivoting; SEQRITE describes MacSync as a MaaS offering supplying tooling and infrastructure to other criminal groups. No CVE identifiers were cited in either report.

  • Delivery chain: ClickFix social-engineering lures combined with malvertising and SEO poisoning (GBHackers) and sponsored search ads (Cyber Security News/SEQRITE), impersonating Claude, ChatGPT, Zoom, and Docker.
  • Victims manually paste curl-to-zsh commands into Terminal, bypassing macOS Gatekeeper and notarization checks.
  • MacSync (formerly Mac.c) emerged April 2025 and is linked to developer 'Mentalpositive' (GBHackers); SEQRITE reports it operates as malware-as-a-service, supplying tooling and infrastructure to other criminal groups.
  • Stager is a 64-bit Mach-O binary with single-byte XOR string obfuscation that daemonizes, polls C2 with custom API-key headers, and streams AppleScript payloads into osascript (GBHackers); SEQRITE describes in-memory AppleScript execution.
  • Stolen data: browser credentials/vaults, Keychain data, SSH keys, session tokens (GBHackers) or session cookies and messaging sessions (Cyber Security News), and cryptocurrency wallets.
  • Exfiltration: staged archives are sent in 10MB HTTP PUT chunks (GBHackers).
  • Persistence via LaunchAgents — described as fake/masquerading by GBHackers and renamed by Cyber Security News (complementary wordings); the malware can also request screen-recording permissions (Cyber Security News).
  • Microsoft identified more than 30 related MacSync domains through behavioral pivoting (GBHackers).

Coverage timeline

  1. · 5d ago
    GBHackers· 58
    Hackers Use ClickFix Lures to Deploy MacSync Stealer and Bypass macOS Security.

    ClickFix malvertising campaigns deliver MacSync, a macOS infostealer sold as MaaS that bypasses Gatekeeper via Terminal commands and steals credentials.

  2. · 5d ago
    Cyber Security News· 55
    Hackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware

    Attackers distribute MacSync macOS infostealer via fake Claude and ChatGPT installers and sponsored search ads, stealing passwords, cookies, keys, and wallets.