Threat reportMalwareTL-2026-2434

ClickFix Lures Deploy MacSync Stealer to Bypass macOS Security

highACTIVE

ClickFix Lures Deploy MacSync Stealer to Bypass macOS (TL-2026-2434), also tracked as Mac.c Stealer, is a high-severity malware campaign, first published 2026-09-10. It has no confirmed attribution, affects Apple macOS, maps to 16 MITRE ATT&CK techniques (T1005, T1027, T1036), and is covered by 9 detection rules and 29 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
16MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
29Indicators of compromise

Key facts for TL-2026-2434

Threat ID
TL-2026-2434
Also known as
Mac.c Stealer
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
government administration, cryptocurrency, technology, finance, generalconsumer
Target regions
united states of america, belgium, india, North America, 005 - South America
Detection rules
9
Indicators of compromise
29

Malware and tooling in ClickFix Lures Deploy MacSync Stealer to Bypass macOS

Malware and tooling: Mac.c Stealer, MacSync Stealer

How ClickFix Lures Deploy MacSync Stealer to Bypass macOS works

Threat actors are running ClickFix social-engineering campaigns that impersonate Claude AI, ChatGPT, Zoom, and other trusted brands to trick macOS users into pasting curl-to-zsh Terminal commands, deploying the MacSync Stealer (formerly Mac.c Stealer) malware-as-a-service. The stealer harvests browser credentials, Keychain data, SSH keys, cloud credentials, and cryptocurrency wallet data, and exfiltrates it over HTTP PUT in 10MB chunks; Microsoft has linked 30+ rotating domains to the operation via behavioral fingerprinting.

MacSync Stealer (publicly known since April 2025 as Mac.c Stealer) is a macOS-focused information-stealer sold as malware-as-a-service, distributed almost exclusively through ClickFix social engineering. Victims encountering malicious search ads, SEO-poisoned pages, or spoofed software portals impersonating Claude AI, ChatGPT/OpenAI Atlas, Zoom, Cloudflare Turnstile, Docker, Cursor, Notion, TradingView, or crypto applications are told a CAPTCHA or installer check failed and are instructed to paste a one-line command into Terminal. That command retrieves a Base64/gzip-encoded payload via curl, which a daemonized zsh stager (using fork()/setsid() to survive Terminal session closure) decodes and executes, ultimately handing off to a dynamic AppleScript payload run in-memory via osascript. This bypasses Gatekeeper and notarization entirely because no file is ever quarantined or executed as a signed application.

The operation evolved across at least three distinct campaigns between November 2025 and February 2026: an initial native Mach-O stager distributed via a fake ChatGPT Atlas installer on Google Sites (November 2025); a second wave abusing legitimate ChatGPT shared-conversation links as redirectors to fake GitHub-themed installers (December 2025); and a third, more evasive Loader-as-a-Service iteration using shell-based loaders, API-key-gated C2, and fully in-memory AppleScript execution (February 2026, observed in Belgium, India, and the Americas). Once running, the AppleScript payload phishes the macOS account password via fake system dialogs, then systematically harvests Chromium/Firefox browser profiles and credentials, macOS Keychain databases, SSH keys, AWS/cloud credentials, Kubernetes configs, Telegram Desktop data, and files from Desktop/Documents/Downloads. It targets 80+ browser-based cryptocurrency wallet extensions and 20+ desktop wallet applications (Exodus, Electrum, Atomic Wallet, Wasabi, Bitcoin Core), and in some builds conditionally trojanizes Ledger Live and Trezor Suite by replacing their app.asar/Info.plist components with versions that inject fake PIN/recovery-phrase capture dialogs.

Collected data is staged under /tmp/sync* paths, compressed into /tmp/osalogging.zip, split into 10MB chunks with the native dd utility, and uploaded via HTTP PUT to attacker infrastructure using static API-key headers and campaign build tokens, with retry logic to tolerate network interruptions; the staged archive and a /tmp/httpcode status file are deleted afterward. Persistence, where used, is established via LaunchAgents masquerading as legitimate Google/Apple service names, with binaries ad-hoc code-signed under identifiers such as com.utils.Launcher. Operators use Telegram bot integrations and PHP stats endpoints to track victim clicks in real time (approximately 29,180 recorded by December 20, 2025) and route Windows visitors to different stealer families via User-Agent-based traffic distribution, confirming a shared MaaS traffic-distribution layer serving multiple affiliates.

Microsoft Defender Experts, RST Cloud, CIS/MS-ISAC, Sophos, and CloudSEK have independently tracked this activity since January 2026. Rather than static domain blocklists, defenders correlate infrastructure through consistent behavioral fingerprints: recurring URI paths (/dynamic?txd=, /gate?buildtxd=, /curl/<token>), macOS-specific User-Agent strings, static API-key headers, and chunked-upload parameters (upload_id, chunk_index, total_chunks) that persist across domain rotation. Microsoft's August 2026 analysis linked over 30 such domains this way. CIS/MS-ISAC issued a Guarded-level advisory in April 2026 after MDBR blocked more than 2.5 million DNS requests tied to the campaign, specifically flagging U.S. State, Local, Tribal, and Territorial (SLTT) government macOS users as targets. Russian-language artifacts recovered from samples suggest a Russian-speaking developer/affiliate ecosystem but do not establish attribution to a named group; a developer alias, 'Mentalpositive,' has been associated with the tool in public research. No CVE applies — the campaign succeeds entirely through social engineering and native OS utilities (Terminal, curl, osascript, dd) rather than a software vulnerability.

MITRE ATT&CK techniques used in TL-2026-2434

Collection

T1005 Data from Local System; T1560 Archive Collected Data

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information

Execution

T1059 Command and Scripting Interpreter; T1204 User Execution

Command and Control

T1071 Application Layer Protocol

Credential Access

T1539 Steal Web Session Cookie; T1552 Unsecured Credentials; T1555 Credentials from Password Stores

Persistence

T1543 Create or Modify System Process

defense-impairment

T1553 Subvert Trust Controls

Initial Access

T1566 Phishing

Resource Development

T1583 Acquire Infrastructure

Impact

T1657 Financial Theft

Affected products and versions in ClickFix Lures Deploy MacSync Stealer to Bypass macOS

  • Apple — macOS
    Vulnerable versions: macOS versions prior to 26.4 (no built-in ClickFix Terminal-paste warning)
    Fixed in: macOS 26.4+ (Terminal paste warning mitigation; does not prevent user-initiated execution)
  • Ledger — Ledger Live
    Vulnerable versions: Any version installed on a MacSync-infected host (app.asar/Info.plist trojanization)
    Fixed in: N/A - reinstall from verified source; treat any recovery phrase entered post-infection as compromised
  • Trezor — Trezor Suite
    Vulnerable versions: Any version installed on a MacSync-infected host (core component replacement)
    Fixed in: N/A - reinstall from verified source; treat any recovery phrase entered post-infection as compromised

Remediation for ClickFix Lures Deploy MacSync Stealer to Bypass macOS

Patches

  • Upgrade to macOS 26.4 or later, which adds Terminal paste warnings that flag ClickFix-style command injection (a mitigating OS control, not a vendor patch for a vulnerability)

Immediate actions

  • Block the known MacSync domains (and monitor for lookalike registrations) at DNS/web proxy layers
  • Alert on curl-to-zsh pipelines and osascript invoked from Terminal.app, especially fork()/setsid()-daemonized shell sessions
  • Hunt managed macOS fleets for /tmp/osalogging.zip, /tmp/sync*, and /tmp/httpcode artifacts
  • Alert on HTTP PUT requests with chunked-upload query parameters (upload_id, chunk_index, total_chunks) or the /dynamic?txd= and /gate?buildtxd= URI patterns
  • Treat any host with Ledger Live or Trezor Suite installed as compromised if MacSync indicators are present, and rotate/move funds tied to any exposed seed phrase or recovery phrase

Workarounds

  • Enforce managed/allow-listed software distribution channels (MDM-approved app catalogs) instead of ad-hoc web downloads
  • Deploy Malicious Domain Blocking and Reporting (MDBR) DNS filtering to catch rotating MacSync infrastructure

Longer-term hardening

  • Deploy EDR with macOS behavioral detection for LaunchAgent creation, Keychain database access followed by archive creation, and osascript-driven credential harvesting
  • Restrict standard-user Terminal access via MDM where operationally feasible
  • Subscribe to MS-ISAC/CIS Indicator Sharing for real-time MacSync IOC feeds (1,000+ IOCs distributed to members as of April 2026)
  • Run continuous user-awareness training that no legitimate CAPTCHA, installer, or AI-tool verification ever requires pasting a command into Terminal

Timeline of ClickFix Lures Deploy MacSync Stealer to Bypass macOS

  • First tracked MacSync ClickFix campaign: malicious Google-sponsored search ads redirected victims to a fake Google Sites page impersonating an OpenAI ChatGPT Atlas browser installer, leading to a Terminal command that deployed a native Mach-O MacSync stager.
  • Second campaign used malvertising on Google Mac-cleanup searches, routing victims through legitimate ChatGPT shared-conversation pages to fake GitHub-themed landing pages instructing Terminal command execution.
  • Tracked MacSync ClickFix domains recorded approximately 29,180 confirmed victim clicks by this date, per stats-endpoint (/app/stats.php) analysis.
  • CloudSEK published technical analysis of MacSync's script-driven stealer architecture and its conditional trojanization of Ledger Live and Trezor Suite via app.asar/Info.plist replacement.
  • Third campaign, observed across Belgium, India, and North/South America, moved to a multistage Loader-as-a-Service model: shell-based loaders, API-key-gated C2, and dynamic in-memory AppleScript payloads.
  • Sophos published 'Evil evolution,' documenting the tactical progression of the three ClickFix/MacSync campaigns and shipping detections OSX/InfoStl-FQ, OSX/InfoStl-FR, and OSX/InfoStl-FH.
  • The Hacker News reported on the fake-AI-installer ClickFix campaigns spreading MacSync, mapping the delivery chain to techniques including Phishing: Spearphishing Link and User Execution: Malicious Link.
  • CIS/MS-ISAC issued a Guarded-level advisory to U.S. State, Local, Tribal, and Territorial government members after Malicious Domain Blocking and Reporting (MDBR) blocked 2.5 million+ DNS requests tied to the MacSync campaign; 1,000+ IOCs were shared with members.
  • RST Cloud documented 4 confirmed MacSync C2 domains sharing a static API key, an early behavioral-pivot precursor to Microsoft's later 30-domain correlation.
  • Microsoft Defender Experts published 'Hunting MacSync Stealer infrastructure through behavioral pivots,' linking 30+ rotating domains via consistent request paths (/dynamic?txd=, /gate?buildtxd=), headers, and chunked-upload parameters.
  • GBHackers reported an active ClickFix campaign impersonating Claude AI, ChatGPT, and Zoom to deploy MacSync Stealer, exfiltrating data via HTTP PUT in 10MB chunks.

Sources cited for ClickFix Lures Deploy MacSync Stealer to Bypass macOS

Detection coverage for TL-2026-2434

As of 2026-09-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2434 across Splunk SPL, Microsoft KQL and Sigma, covering 29 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
29 indicators of compromise · Red and above. Compare plans

Community OSINT corroboration for TL-2026-2434

3 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats