# ClickFix Lures Deploy MacSync Stealer to Bypass macOS Security

> Threat actors are running ClickFix social-engineering campaigns that impersonate Claude AI, ChatGPT, Zoom, and other trusted brands to trick macOS users into pasting curl-to-zsh Terminal commands, deploying the MacSync Stealer (formerly Mac.c Stealer) malware-as-a-service. The stealer harvests browser credentials, Keychain data, SSH keys, cloud credentials, and cryptocurrency wallet data, and exfiltrates it over HTTP PUT in 10MB chunks; Microsoft has linked 30+ rotating domains to the operation via behavioral fingerprinting.

- **Published:** 2026-09-10T00:00:00Z
- **Last reviewed:** 2026-09-10T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2434
- **ID:** TL-2026-2434
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 29 (full data via the Threadlinqs MCP server — Purple tier)

## Description

MacSync Stealer (publicly known since April 2025 as Mac.c Stealer) is a macOS-focused information-stealer sold as malware-as-a-service, distributed almost exclusively through ClickFix social engineering. Victims encountering malicious search ads, SEO-poisoned pages, or spoofed software portals impersonating Claude AI, ChatGPT/OpenAI Atlas, Zoom, Cloudflare Turnstile, Docker, Cursor, Notion, TradingView, or crypto applications are told a CAPTCHA or installer check failed and are instructed to paste a one-line command into Terminal. That command retrieves a Base64/gzip-encoded payload via curl, which a daemonized zsh stager (using fork()/setsid() to survive Terminal session closure) decodes and executes, ultimately handing off to a dynamic AppleScript payload run in-memory via osascript. This bypasses Gatekeeper and notarization entirely because no file is ever quarantined or executed as a signed application.

The operation evolved across at least three distinct campaigns between November 2025 and February 2026: an initial native Mach-O stager distributed via a fake ChatGPT Atlas installer on Google Sites (November 2025); a second wave abusing legitimate ChatGPT shared-conversation links as redirectors to fake GitHub-themed installers (December 2025); and a third, more evasive Loader-as-a-Service iteration using shell-based loaders, API-key-gated C2, and fully in-memory AppleScript execution (February 2026, observed in Belgium, India, and the Americas). Once running, the AppleScript payload phishes the macOS account password via fake system dialogs, then systematically harvests Chromium/Firefox browser profiles and credentials, macOS Keychain databases, SSH keys, AWS/cloud credentials, Kubernetes configs, Telegram Desktop data, and files from Desktop/Documents/Downloads. It targets 80+ browser-based cryptocurrency wallet extensions and 20+ desktop wallet applications (Exodus, Electrum, Atomic Wallet, Wasabi, Bitcoin Core), and in some builds conditionally trojanizes Ledger Live and Trezor Suite by replacing their app.asar/Info.plist components with versions that inject fake PIN/recovery-phrase capture dialogs.

Collected data is staged under /tmp/sync* paths, compressed into /tmp/osalogging.zip, split into 10MB chunks with the native dd utility, and uploaded via HTTP PUT to attacker infrastructure using static API-key headers and campaign build tokens, with retry logic to tolerate network interruptions; the staged archive and a /tmp/httpcode status file are deleted afterward. Persistence, where used, is established via LaunchAgents masquerading as legitimate Google/Apple service names, with binaries ad-hoc code-signed under identifiers such as com.utils.Launcher. Operators use Telegram bot integrations and PHP stats endpoints to track victim clicks in real time (approximately 29,180 recorded by December 20, 2025) and route Windows visitors to different stealer families via User-Agent-based traffic distribution, confirming a shared MaaS traffic-distribution layer serving multiple affiliates.

Microsoft Defender Experts, RST Cloud, CIS/MS-ISAC, Sophos, and CloudSEK have independently tracked this activity since January 2026. Rather than static domain blocklists, defenders correlate infrastructure through consistent behavioral fingerprints: recurring URI paths (/dynamic?txd=, /gate?buildtxd=, /curl/<token>), macOS-specific User-Agent strings, static API-key headers, and chunked-upload parameters (upload_id, chunk_index, total_chunks) that persist across domain rotation. Microsoft's August 2026 analysis linked over 30 such domains this way. CIS/MS-ISAC issued a Guarded-level advisory in April 2026 after MDBR blocked more than 2.5 million DNS requests tied to the campaign, specifically flagging U.S. State, Local, Tribal, and Territorial (SLTT) government macOS users as targets. Russian-language artifacts recovered from samples suggest a Russian-speaking developer/affiliate ecosystem but do not establish attribution to a named group; a developer alias, 'Mentalpositive,' has been associated with the tool in public research. No CVE applies — the campaign succeeds entirely through social engineering and native OS utilities (Terminal, curl, osascript, dd) rather than a software vulnerability.

## MITRE ATT&CK

- T1583 Acquire Infrastructure
- T1566 Phishing
- T1204 User Execution
- T1059 Command and Scripting Interpreter
- T1543 Create or Modify System Process
- T1553 Subvert Trust Controls
- T1036 Masquerading
- T1027 Obfuscated Files or Information
- T1140 Deobfuscate/Decode Files or Information
- T1555 Credentials from Password Stores
- T1552 Unsecured Credentials
- T1539 Steal Web Session Cookie
- T1005 Data from Local System
- T1560 Archive Collected Data
- T1071 Application Layer Protocol
- T1657 Financial Theft

## Sources

- [Hackers Use ClickFix Lures to Deploy MacSync Stealer and Bypass macOS Security](https://gbhackers.com/clickfix-lures-target-macos/)
- [Hunting MacSync Stealer infrastructure through behavioral pivots](https://www.microsoft.com/en-us/security/blog/2026/08/18/hunting-macsync-stealer-infrastructure-through-behavioral-pivots/)
- [Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure](https://thehackernews.com/2026/08/microsoft-links-30-rotating-domains-to.html)
- [ClickFix Campaigns Spread MacSync macOS Infostealer via Fake AI Tool Installers](https://thehackernews.com/2026/03/clickfix-campaigns-spread-macsync-macos.html)
- [Evil evolution: ClickFix and macOS infostealers](https://www.sophos.com/en-us/blog/evil-evolution-clickfix-and-macos-infostealers)
- [MacSync Stealer Campaign Impacting U.S. SLTT macOS Users](https://www.cisecurity.org/insights/blog/macsync-stealer-campaign-impacting-us-sltt-macos-users)
- [Inside MacSync's Script-Driven Stealer and Hardware Wallet App Trojanization](https://www.cloudsek.com/blog/inside-macsyncs-script-driven-stealer-and-hardware-wallet-app-trojanization)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2434
