Deep Analysis of the Malicious AppleScript Payload (MacSync Stealer)
labs.cognisys.group | blog | #threat-intelligence | #macos | #malware-analysis | #infostealer | #clickfix | #applescript
Summary
Deep dive into a macOS ClickFix campaign: the memory-resident MacSync Stealer, delivered via obfuscated Zsh and AppleScript, harvests passwords, browser data and crypto wallets. IOCs included.
- Published
- Collected
Skip to content