Verified X Ad Spreads Mac Infostealer (Atomic Stealer Variant "MacSync"/DigitStealer) via Fake DynamicLake App; ConsentFix OAuth Technique Enables Microsoft Account Takeover — Threadlinqs Intelligence
As of 2026-07-03, Verified X Ad Spreads Mac Infostealer (Atomic Stealer Variant "MacSync"/DigitStealer) via Fake DynamicLake App; ConsentFix OAuth Technique Enables Microsoft Account Takeover is a high-severity malware threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 30 indicators of compromise.
Threat ID: TL-2026-1095 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
A sponsored ad placed through a verified, high-follower X (Twitter) account impersonated the Mac utility DynamicLake and redirected victims to the lookalike domain dynamicmacisland[.]com, where a
On 2026-07-03, Malwarebytes Labs (corroborated same-day/previous-day by 9to5Mac) reported that a sponsored advertisement running through a verified, high-follower X account impersonated DynamicLake, a legitimate macOS utility that turns a MacBook's notch into a Dynamic-Island-style widget. Clicking the ad redirected victims to dynamicmacisland[.]com, a malicious lookalike domain with no ties to the real app. The site used a ClickFix-style lure instructing visitors to open Terminal and paste an installation one-liner, which silently installed malware. Jamf Threat Labs identified the payload as a variant of Atomic Stealer (AMOS) that it tracks as "MacSync," with related infections by a second family, "DigitStealer," also observed in the same wave. Jamf reported the ad to X, which removed it. This is described as the first known instance of malware distributed through paid/sponsored advertising on X.
MacSync and DigitStealer are both mature, actively developed macOS infostealer families with a documented history predating this specific campaign, evidence the ad-borne payload sits within an established malware-as-a-service (MaaS) operation rather than a one-off tool. Jamf Threat Labs first documented DigitStealer on 2025-11-13, distributed via an unsigned disk image ("DynamicLake.dmg", containing a "Drag Into Terminal" lure) and via YouTube videos impersonating DynamicLake; a related lookalike domain, dynamiclake[.]org, was used in that wave. DigitStealer runs a six-stage chain (bash dropper with Apple-Silicon/anti-VM fingerprinting via sysctl, an AppleScript fake-password-prompt credential stealer, an obfuscated JXA browser/wallet extractor, a JXA Ledger Live ASAR-patching module, a bash LaunchAgent persistence installer, and a JXA backdoor that polls its C2 roughly every 10 seconds) and targets Chrome/Brave/Edge/Firefox credentials, Keychain, Ledger/Electrum/Exodus/Coinami wallets, OpenVPN/Tunnelblick configs, and Telegram data, while running `tccutil reset All` to strip macOS TCC privacy protections. Its C2 (goldenticketshop[.]com and diamondpickaxeforge[.]com, with infrastructure IP 80.78.25[.]205) is hosted on a single Swedish network with consistently reused .com domains and Tucows registrations, indicating a small, closely managed operator team. MacSync separately evolved from a manual ClickFix/drag-to-terminal dropper (observed via a fake-Homebrew search ad in a December 2025 SANS ISC capture, C2 glowmedaesthetics[.]com) into a code-signed and Apple-notarized Swift Mach-O binary ("runtimectl", masquerading via the state directory name "UserSyncWorker") distributed inside "zk-call-messenger-installer-3.9.2-lts.dmg" from zkcall[.]net; Apple subsequently revoked the abused Developer Team ID (GNJLS3UYZ4) after Jamf's report. That dropper rate-limits and fetches a second-stage payload from gatemaden[.]space, staging data locally (e.g. /tmp/osalogging.zip via `ditto`) before exfiltration. By May 2026, SOC Prime documented MacSync operating a rotating pool of roughly a dozen C2 domains sharing a static API key and per-build hex tokens, consistent with a MaaS model serving multiple distribution campaigns (malvertising, fake installers, and the DynamicLake/dynamicmacisland[.]com lure documented here).
The same Malwarebytes report separately covers ConsentFix (also referred to as AuthCodeFix), a browser-native, ClickFix-styled OAuth authorization-code phishing technique first disclosed by Push Security. Victims land on a compromised or SEO-poisoned high-ranking website, pass a fake Cloudflare Turnstile-style CAPTCHA that harvests their business email address and filters out bots/analysts, and are then instructed to click a "Sign in" button. This opens a genuine Microsoft/Azure login flow for the Azure CLI application (client/App ID 04b07795-8ddb-461a-bbee-02f9e1bf7b46), a first-party Microsoft application in the "Family of Client IDs" (FOCI) that is implicitly trusted and pre-consented in every tenant, so no consent-approval scree
Target sectors: technology, financial services, cryptocurrency, government administration, professional services, consumer
Target regions: Global
Detections & IOCs
As of 2026-08-24, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 30 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
5 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
MALWARE, HIGH, threat intelligence, cybersecurity, T1589.002, T1591.004, T1583.001, T1583.004, T1583.008, T1587.002, T1586.001, T1608.001, T1584.004, T1189