SlowMist: Highly destructive malware appears on macOS, capable of stealing users' encrypted wallets and other sensitive data

robot
Abstract generation in progress

Golden Finance reports that on April 22, according to SlowMist monitoring, a malicious software called “MacSync Stealer” (v1.1.2) is currently active and highly destructive.
This malware targets macOS users, stealing sensitive data including crypto wallets, browser credentials, system keychains, and infrastructure keys (SSH/AWS/K8s).
The malware uses fake AppleScript system dialog boxes for phishing, and after data leaks, displays a fake error message saying “Not Supported.”
It has immediately synchronized this IOC (Indicators of Compromise) with clients.
SlowMist reminds users not to execute unverified macOS scripts and to stay highly alert to unexpected system password prompts.
If a attack is suspected, immediate remediation is required: change all infrastructure credentials (SSH/AWS/K8s), invalidate exposed keychains, and quickly migrate crypto assets to a secure wallet.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin