Cybersecurity News
Filters
Filtered by tag: macos malware × Clear
Fake CAPTCHA Tricks Mac Users Into Installing a Backdoor That Steals Passwords and Mines Crypto
Matched: cryptocurrency
A ClickFix campaign is targeting Mac users with a fake CAPTCHA page styled as "TrustKey" that tricks victims into running a malicious Terminal command. The command fetches an AppleScript payload via Cloudflare Workers, installs a persistent LaunchAgent, and uses blockchain-based EtherHiding to locate its command server. The backdoor steals browser credentials, keychain data, and crypto wallet information, while also deploying XMRig to mine Monero. Any CAPTCHA requesting Terminal access should be treated as malicious.
MacSync Stealer: How a Google Search for Claude Led to a macOS Infostealer
Researchers at Huntress discovered a macOS infostealer called MacSync Stealer being distributed through fake download pages impersonating Claude Code. Users searching for the AI tool were directed to malicious sites that delivered the malware, which steals sensitive data. Huntress SOC analysts reverse engineered the threat and published a full breakdown of its behavior and distribution method.
Reverse Engineering the Six Stages of MacSync Stealer and RAT
Researchers reverse-engineered MacSync, a six-stage macOS malware combining stealer and remote access trojan capabilities. The sample was recovered from attacker infrastructure after the compromised host went offline. Analysis traced its execution chain across all six stages, revealing how it exfiltrates data and maintains remote access on infected machines.
