SlowMist: macOS malware "MacSync Stealer" is active and highly destructive

robot
Abstract generation in progress

ChainCatcher message: According to blockchain security firm SlowMist, MistEye has received threat intelligence from the community indicating that a malicious software called “MacSync Stealer” (v1.1.2) is active and highly destructive. This malware targets macOS users, stealing sensitive data including crypto wallets, browser credentials, system keychains, and infrastructure keys (SSH/AWS/K8s).

The malware uses fake AppleScript system dialog boxes for phishing and displays false “unsupported” error messages after data leaks. It has immediately synchronized this IOC (Indicator of Compromise) with clients. Do not execute unverified macOS scripts, and remain highly alert to unexpected system password prompts. If an attack is suspected, immediate remediation is required: change all infrastructure credentials (SSH/AWS/K8s), invalidate exposed keychains, and quickly migrate crypto assets to secure wallets.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin