ClickFix Lures Deliver MacSync macOS Infostealer Through Fake Claude, ChatGPT, Zoom, and Docker Installers
Threat actors are distributing MacSync, a macOS infostealer sold as malware-as-a-service, via ClickFix social-engineering lures, malvertising, SEO poisoning, and sponsored search ads impersonating Claude, ChatGPT, Zoom, and Docker. Victims paste curl-to-zsh…
Per 2026-09-10 reports from GBHackers and Cyber Security News (citing SEQRITE), a malware-as-a-service campaign pushes MacSync, a macOS infostealer, through ClickFix social-engineering lures, malvertising, SEO poisoning, and sponsored search ads impersonating brands including Claude, ChatGPT, Zoom, and Docker. Victims are tricked into manually pasting curl-to-zsh commands into Terminal, sidestepping Gatekeeper and notarization checks. The resulting stager is a 64-bit Mach-O binary with single-byte XOR string obfuscation that daemonizes, polls its C2 server with custom API-key headers, and streams AppleScript payloads into osascript for in-memory execution. MacSync (formerly Mac.c, emerged April 2025, linked to developer 'Mentalpositive') harvests browser credentials and vaults, Keychain data, SSH keys, session tokens/cookies, messaging sessions, and cryptocurrency wallets, then exfiltrates staged archives in 10MB HTTP PUT chunks. It persists via LaunchAgents (described as fake/masquerading by GBHackers and renamed by Cyber Security News) and can request screen-recording permissions. GBHackers, citing Microsoft, reports more than 30 related MacSync domains identified through behavioral pivoting; SEQRITE describes MacSync as a MaaS offering supplying tooling and infrastructure to other criminal groups. No CVE identifiers were cited in either report.
- Delivery chain: ClickFix social-engineering lures combined with malvertising and SEO poisoning (GBHackers) and sponsored search ads (Cyber Security News/SEQRITE), impersonating Claude, ChatGPT, Zoom, and Docker.
- Victims manually paste curl-to-zsh commands into Terminal, bypassing macOS Gatekeeper and notarization checks.
- MacSync (formerly Mac.c) emerged April 2025 and is linked to developer 'Mentalpositive' (GBHackers); SEQRITE reports it operates as malware-as-a-service, supplying tooling and infrastructure to other criminal groups.
- Stager is a 64-bit Mach-O binary with single-byte XOR string obfuscation that daemonizes, polls C2 with custom API-key headers, and streams AppleScript payloads into osascript (GBHackers); SEQRITE describes in-memory AppleScript execution.
- Stolen data: browser credentials/vaults, Keychain data, SSH keys, session tokens (GBHackers) or session cookies and messaging sessions (Cyber Security News), and cryptocurrency wallets.
- Exfiltration: staged archives are sent in 10MB HTTP PUT chunks (GBHackers).
- Persistence via LaunchAgents — described as fake/masquerading by GBHackers and renamed by Cyber Security News (complementary wordings); the malware can also request screen-recording permissions (Cyber Security News).
- Microsoft identified more than 30 related MacSync domains through behavioral pivoting (GBHackers).
Coverage timelineoldest first · each row is one article
- · 5d agoHackers Use ClickFix Lures to Deploy MacSync Stealer and Bypass macOS Security.
GBHackers· 58
ClickFix malvertising campaigns deliver MacSync, a macOS infostealer sold as MaaS that bypasses Gatekeeper via Terminal commands and steals credentials.
- · 5d agoHackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware
Cyber Security News· 55
Attackers distribute MacSync macOS infostealer via fake Claude and ChatGPT installers and sponsored search ads, stealing passwords, cookies, keys, and wallets.