Threat reportMalwareTL-2026-2434
ClickFix Lures Deploy MacSync Stealer to Bypass macOS Security
ClickFix Lures Deploy MacSync Stealer to Bypass macOS (TL-2026-2434), also tracked as Mac.c Stealer, is a high-severity malware campaign, first published 2026-09-10. It has no confirmed attribution, affects Apple macOS, maps to 16 MITRE ATT&CK techniques (T1005, T1027, T1036), and is covered by 9 detection rules and 29 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 16MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 29Indicators of compromise
Key facts for TL-2026-2434
- Threat ID
- TL-2026-2434
- Also known as
- Mac.c Stealer
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- government administration, cryptocurrency, technology, finance, generalconsumer
- Target regions
- united states of america, belgium, india, North America, 005 - South America
- Detection rules
- 9
- Indicators of compromise
- 29
Malware and tooling in ClickFix Lures Deploy MacSync Stealer to Bypass macOS
Malware and tooling: Mac.c Stealer, MacSync Stealer
How ClickFix Lures Deploy MacSync Stealer to Bypass macOS works
Threat actors are running ClickFix social-engineering campaigns that impersonate Claude AI, ChatGPT, Zoom, and other trusted brands to trick macOS users into pasting curl-to-zsh Terminal commands, deploying the MacSync Stealer (formerly Mac.c Stealer) malware-as-a-service. The stealer harvests browser credentials, Keychain data, SSH keys, cloud credentials, and cryptocurrency wallet data, and exfiltrates it over HTTP PUT in 10MB chunks; Microsoft has linked 30+ rotating domains to the operation via behavioral fingerprinting.
MacSync Stealer (publicly known since April 2025 as Mac.c Stealer) is a macOS-focused information-stealer sold as malware-as-a-service, distributed almost exclusively through ClickFix social engineering. Victims encountering malicious search ads, SEO-poisoned pages, or spoofed software portals impersonating Claude AI, ChatGPT/OpenAI Atlas, Zoom, Cloudflare Turnstile, Docker, Cursor, Notion, TradingView, or crypto applications are told a CAPTCHA or installer check failed and are instructed to paste a one-line command into Terminal. That command retrieves a Base64/gzip-encoded payload via curl, which a daemonized zsh stager (using fork()/setsid() to survive Terminal session closure) decodes and executes, ultimately handing off to a dynamic AppleScript payload run in-memory via osascript. This bypasses Gatekeeper and notarization entirely because no file is ever quarantined or executed as a signed application.
The operation evolved across at least three distinct campaigns between November 2025 and February 2026: an initial native Mach-O stager distributed via a fake ChatGPT Atlas installer on Google Sites (November 2025); a second wave abusing legitimate ChatGPT shared-conversation links as redirectors to fake GitHub-themed installers (December 2025); and a third, more evasive Loader-as-a-Service iteration using shell-based loaders, API-key-gated C2, and fully in-memory AppleScript execution (February 2026, observed in Belgium, India, and the Americas). Once running, the AppleScript payload phishes the macOS account password via fake system dialogs, then systematically harvests Chromium/Firefox browser profiles and credentials, macOS Keychain databases, SSH keys, AWS/cloud credentials, Kubernetes configs, Telegram Desktop data, and files from Desktop/Documents/Downloads. It targets 80+ browser-based cryptocurrency wallet extensions and 20+ desktop wallet applications (Exodus, Electrum, Atomic Wallet, Wasabi, Bitcoin Core), and in some builds conditionally trojanizes Ledger Live and Trezor Suite by replacing their app.asar/Info.plist components with versions that inject fake PIN/recovery-phrase capture dialogs.
Collected data is staged under /tmp/sync* paths, compressed into /tmp/osalogging.zip, split into 10MB chunks with the native dd utility, and uploaded via HTTP PUT to attacker infrastructure using static API-key headers and campaign build tokens, with retry logic to tolerate network interruptions; the staged archive and a /tmp/httpcode status file are deleted afterward. Persistence, where used, is established via LaunchAgents masquerading as legitimate Google/Apple service names, with binaries ad-hoc code-signed under identifiers such as com.utils.Launcher. Operators use Telegram bot integrations and PHP stats endpoints to track victim clicks in real time (approximately 29,180 recorded by December 20, 2025) and route Windows visitors to different stealer families via User-Agent-based traffic distribution, confirming a shared MaaS traffic-distribution layer serving multiple affiliates.
Microsoft Defender Experts, RST Cloud, CIS/MS-ISAC, Sophos, and CloudSEK have independently tracked this activity since January 2026. Rather than static domain blocklists, defenders correlate infrastructure through consistent behavioral fingerprints: recurring URI paths (/dynamic?txd=, /gate?buildtxd=, /curl/<token>), macOS-specific User-Agent strings, static API-key headers, and chunked-upload parameters (upload_id, chunk_index, total_chunks) that persist across domain rotation. Microsoft's August 2026 analysis linked over 30 such domains this way. CIS/MS-ISAC issued a Guarded-level advisory in April 2026 after MDBR blocked more than 2.5 million DNS requests tied to the campaign, specifically flagging U.S. State, Local, Tribal, and Territorial (SLTT) government macOS users as targets. Russian-language artifacts recovered from samples suggest a Russian-speaking developer/affiliate ecosystem but do not establish attribution to a named group; a developer alias, 'Mentalpositive,' has been associated with the tool in public research. No CVE applies — the campaign succeeds entirely through social engineering and native OS utilities (Terminal, curl, osascript, dd) rather than a software vulnerability.
MITRE ATT&CK techniques used in TL-2026-2434
Collection
T1005 Data from Local System; T1560 Archive Collected Data
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information
Execution
T1059 Command and Scripting Interpreter; T1204 User Execution
Command and Control
T1071 Application Layer Protocol
Credential Access
T1539 Steal Web Session Cookie; T1552 Unsecured Credentials; T1555 Credentials from Password Stores
Persistence
T1543 Create or Modify System Process
defense-impairment
Initial Access
Resource Development
Impact
Affected products and versions in ClickFix Lures Deploy MacSync Stealer to Bypass macOS
- Apple — macOS
Vulnerable versions: macOS versions prior to 26.4 (no built-in ClickFix Terminal-paste warning)
Fixed in: macOS 26.4+ (Terminal paste warning mitigation; does not prevent user-initiated execution) - Ledger — Ledger Live
Vulnerable versions: Any version installed on a MacSync-infected host (app.asar/Info.plist trojanization)
Fixed in: N/A - reinstall from verified source; treat any recovery phrase entered post-infection as compromised - Trezor — Trezor Suite
Vulnerable versions: Any version installed on a MacSync-infected host (core component replacement)
Fixed in: N/A - reinstall from verified source; treat any recovery phrase entered post-infection as compromised
Remediation for ClickFix Lures Deploy MacSync Stealer to Bypass macOS
Patches
- Upgrade to macOS 26.4 or later, which adds Terminal paste warnings that flag ClickFix-style command injection (a mitigating OS control, not a vendor patch for a vulnerability)
Immediate actions
- Block the known MacSync domains (and monitor for lookalike registrations) at DNS/web proxy layers
- Alert on curl-to-zsh pipelines and osascript invoked from Terminal.app, especially fork()/setsid()-daemonized shell sessions
- Hunt managed macOS fleets for /tmp/osalogging.zip, /tmp/sync*, and /tmp/httpcode artifacts
- Alert on HTTP PUT requests with chunked-upload query parameters (upload_id, chunk_index, total_chunks) or the /dynamic?txd= and /gate?buildtxd= URI patterns
- Treat any host with Ledger Live or Trezor Suite installed as compromised if MacSync indicators are present, and rotate/move funds tied to any exposed seed phrase or recovery phrase
Workarounds
- Enforce managed/allow-listed software distribution channels (MDM-approved app catalogs) instead of ad-hoc web downloads
- Deploy Malicious Domain Blocking and Reporting (MDBR) DNS filtering to catch rotating MacSync infrastructure
Longer-term hardening
- Deploy EDR with macOS behavioral detection for LaunchAgent creation, Keychain database access followed by archive creation, and osascript-driven credential harvesting
- Restrict standard-user Terminal access via MDM where operationally feasible
- Subscribe to MS-ISAC/CIS Indicator Sharing for real-time MacSync IOC feeds (1,000+ IOCs distributed to members as of April 2026)
- Run continuous user-awareness training that no legitimate CAPTCHA, installer, or AI-tool verification ever requires pasting a command into Terminal
Timeline of ClickFix Lures Deploy MacSync Stealer to Bypass macOS
- First tracked MacSync ClickFix campaign: malicious Google-sponsored search ads redirected victims to a fake Google Sites page impersonating an OpenAI ChatGPT Atlas browser installer, leading to a Terminal command that deployed a native Mach-O MacSync stager.
- Second campaign used malvertising on Google Mac-cleanup searches, routing victims through legitimate ChatGPT shared-conversation pages to fake GitHub-themed landing pages instructing Terminal command execution.
- Tracked MacSync ClickFix domains recorded approximately 29,180 confirmed victim clicks by this date, per stats-endpoint (/app/stats.php) analysis.
- CloudSEK published technical analysis of MacSync's script-driven stealer architecture and its conditional trojanization of Ledger Live and Trezor Suite via app.asar/Info.plist replacement.
- Third campaign, observed across Belgium, India, and North/South America, moved to a multistage Loader-as-a-Service model: shell-based loaders, API-key-gated C2, and dynamic in-memory AppleScript payloads.
- Sophos published 'Evil evolution,' documenting the tactical progression of the three ClickFix/MacSync campaigns and shipping detections OSX/InfoStl-FQ, OSX/InfoStl-FR, and OSX/InfoStl-FH.
- The Hacker News reported on the fake-AI-installer ClickFix campaigns spreading MacSync, mapping the delivery chain to techniques including Phishing: Spearphishing Link and User Execution: Malicious Link.
- CIS/MS-ISAC issued a Guarded-level advisory to U.S. State, Local, Tribal, and Territorial government members after Malicious Domain Blocking and Reporting (MDBR) blocked 2.5 million+ DNS requests tied to the MacSync campaign; 1,000+ IOCs were shared with members.
- RST Cloud documented 4 confirmed MacSync C2 domains sharing a static API key, an early behavioral-pivot precursor to Microsoft's later 30-domain correlation.
- Microsoft Defender Experts published 'Hunting MacSync Stealer infrastructure through behavioral pivots,' linking 30+ rotating domains via consistent request paths (/dynamic?txd=, /gate?buildtxd=), headers, and chunked-upload parameters.
- GBHackers reported an active ClickFix campaign impersonating Claude AI, ChatGPT, and Zoom to deploy MacSync Stealer, exfiltrating data via HTTP PUT in 10MB chunks.
Sources cited for ClickFix Lures Deploy MacSync Stealer to Bypass macOS
- Hackers Use ClickFix Lures to Deploy MacSync Stealer and Bypass macOS Security
- Hunting MacSync Stealer infrastructure through behavioral pivots
- Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure
- ClickFix Campaigns Spread MacSync macOS Infostealer via Fake AI Tool Installers
- Evil evolution: ClickFix and macOS infostealers
- MacSync Stealer Campaign Impacting U.S. SLTT macOS Users
- Inside MacSync's Script-Driven Stealer and Hardware Wallet App Trojanization
Detection coverage for TL-2026-2434
As of 2026-09-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2434 across Splunk SPL, Microsoft KQL and Sigma, covering 29 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-2434
3 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.