Slow Fog: Highly Destructive Malware on macOS Can Steal Sensitive Data Including Cryptocurrency Wallets

robot
Abstract generation in progress

On April 22, Slow Fog reported that a highly destructive malware named ‘MacSync Stealer’ (v1.1.2) is currently active. This malware targets macOS users and steals sensitive data, including cryptocurrency wallets, browser credentials, system keychains, and infrastructure keys (SSH/AWS/K8s). The malware employs a spoofed AppleScript system dialog for phishing and displays a fake error message stating ‘unsupported’ after data leakage. It has immediately synchronized this IOC (Indicator of Compromise) with clients. Slow Fog advises users not to execute unverified macOS scripts and to remain highly vigilant against unexpected system password prompts. If an attack is suspected, immediate remediation is necessary: change all infrastructure credentials (SSH/AWS/K8s), invalidate any exposed keychains, and quickly migrate cryptocurrency assets to secure wallets.

This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin