Mark RadarMARK RADAR
About
EN
Sign in
Event File CRYPTO Cryptocurrency Wallets

MacSync Targets macOS Crypto Wallets and Cloud Credentials

1 reports · First detected 2026-08-20 · Last active 2026-08-20

MacSync is an information stealer targeting macOS users through terminal-based social engineering, prompting victims to run malicious commands themselves. Microsoft’s disclosure highlights the growing value of data stored on Macs, including cryptocurrency wallets, system keychains and cloud-service credentials. Such information can be monetized directly or used to gain deeper access to personal accounts and corporate infrastructure.

Microsoft’s latest analysis found that MacSync searches infected systems for crypto wallet data, macOS Keychain records and cloud credentials before exfiltrating the material in separate chunks. The malware also rotates its command-and-control, or C2, domains, making domain-based blocking and tracking more difficult. Chunked uploads can further reduce the chance that unusually large outbound transfers trigger conventional security monitoring.

All Coverage

1 original reports

The Backstory

The history behind this event
ClickFix Campaign Fingerprints Mac Users to Deliver Crypto-Stealing Malware2026-08-07 · 1 reports · similarity 0.83

ClickFix is a social-engineering technique that presents bogus errors or CAPTCHA checks and persuades users to run commands on their own devices. Once largely associated with Windows, the method has increasingly targeted macOS without needing to exploit a software flaw. The user-initiated execution can sidestep conventional web defenses, allowing information stealers to pursue cryptocurrency wallets, browser passwords, session data and corporate credentials.

Microsoft said on Aug. 5, 2026 that the macOS campaign had used more than 250 domains and added a server-side browser-fingerprinting gate to screen out automated scanners and security sandboxes. Mac visitors who pass the checks are shown instructions to paste a malicious command into Terminal. That command ultimately installs Atomic macOS Stealer, or AMOS, which can harvest cryptocurrency-wallet data, account credentials and other sensitive information.

ClickLock Mac Malware Targets Crypto Wallets Across 33 Countries2026-07-20 · 1 reports · similarity 0.81

ClickLock Stealer is a newly documented macOS information stealer that relies on social engineering rather than a software exploit. It is believed to arrive through ClickFix-style pages masquerading as Cloudflare verification checks, which persuade users to paste a malicious command into Terminal. The campaign matters because it turns trusted system prompts and built-in tools against Mac users, exposing browser credentials, password-manager data, Keychain material and cryptocurrency holdings while leaving a persistent backdoor.

Group-IB disclosed the malware on July 16, 2026, after finding a sample uploaded to VirusTotal on June 9 with zero detections at the time of analysis. The operation has been active since May and has targeted at least 100 victims in 33 countries, more than half in Europe. ClickLock can kill visible applications every 210 milliseconds until a user submits a login password, while harvesting data from 31 crypto-wallet browser extensions, eight desktop wallets and blockchain addresses across six networks for exfiltration through Telegram.

macOS Malware Hijacks Telegram Sessions, Targets Crypto Wallets2026-07-17 · 1 reports · similarity 0.82

As the crypto community increasingly relies on Telegram to manage assets, securing the messaging platform has become critical. macOS, once considered relatively secure, is now facing targeted malware attacks. Such attacks can directly steal locally authenticated session data and browser wallet extensions, bypassing two-factor authentication (2FA) and posing a serious threat to digital-asset holders worldwide.

Blockchain security company SlowMist warned on July 15, 2026, that malware targeting macOS was seeking to hijack Telegram desktop sessions. The malware targets more than a dozen major cryptocurrency wallets and copies data from their browser extensions. It also uses fake hardware-wallet applications purporting to be from Ledger and Trezor to trick users into disclosing seed phrases and steal their assets.

macOS Stealer CrashStealer Poses as Crash Reporter to Target Crypto Wallets2026-07-14 · 1 reports · similarity 0.83

Cybersecurity company Jamf has uncovered CrashStealer, a new type of macOS malware that masquerades as the system's built-in crash-reporting tool to trick users into entering their passwords and granting access to the system keychain. The malware poses a significant threat because it specifically targets as many as 80 types of cryptocurrency wallets as well as browser credentials. It is also the first such malware to be developed using native C++ code, making it harder for traditional antivirus software to detect.

According to a Jamf Threat Labs investigation published in July 2026, researchers spotted signs that the malware was under development as early as May 2026 and found it had entered active deployment by early July. The malware bypassed system defenses using a malicious certificate that had passed Apple's notarization process. Apple revoked the associated developer certificates in mid-July to prevent further harm.

PamStealer Poses as macOS Tool to Steal Crypto Wallets2026-07-09 · 1 reports · similarity 0.85

Malware attacks targeting Apple users have recently become frequent on macOS. A new infostealer called PamStealer masquerades as the popular open-source clipboard utility Maccy and uses macOS’s built-in Pluggable Authentication Modules, or PAM, mechanism to verify administrator privileges. It can specifically steal browser credentials and cryptocurrency wallets. Its ability to bypass system safeguards poses a major threat to users’ digital assets.

Jamf Threat Labs disclosed the malware in July 2026. Attackers created the fake website maccyapp[.]com to trick users into downloading it. The software packages an AppleScript that, when users follow instructions to run it in Script Editor, downloads a second-stage payload written in Rust. The payload impersonates system applications such as Finder to evade detection and steal private data in the background.

macOS Stealer Reaper Impersonates Tech Giants and Targets Crypto Wallets2026-05-19 · 2 reports · similarity 0.85

macOS users are increasingly being targeted by information-stealing malware, with attackers often posing as Apple, Microsoft or Google update alerts to lower their guard. Reaper is particularly significant because it both creates a system backdoor and targets cryptocurrency wallets such as MetaMask and Phantom, potentially gaining access to credentials, private keys and control of assets.

A cybersecurity company recently disclosed that Reaper uses a mix of fake Apple, Microsoft and Google software updates to trick macOS users into installing it, after which it collects wallet data and steals assets. Existing reports have not disclosed the organization that discovered it, the exact disclosure date, the number of victims or the value of losses. Users should update software only through official channels.

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)