Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Deep Analysis of the Malicious AppleScript Payload (MacSync Stealer)

Summary

Deep dive into a macOS ClickFix campaign: the memory-resident MacSync Stealer, delivered via obfuscated Zsh and AppleScript, harvests passwords, browser data and crypto wallets. IOCs included.
Published
Collected

original ↗

Related coverage

back