According to Microsoft’s security research team, since late 2025, attackers have been distributing fake macOS troubleshooting guides on platforms including Medium, Craft, and Squarespace to trick users into running malicious terminal commands. The commands download and execute malware designed to steal cryptocurrency wallet keys from Exodus, Ledger, and Trezor, along with iCloud data and saved passwords from Chrome and Firefox.
The malware families involved include AMOS, Macsync, and SHub Stealer. In some cases, attackers also delete legitimate wallet applications and replace them with trojanized versions. Apple has added protection in macOS 26.4 to block pasting of potentially malicious commands.
Related News
Anthropic Code Mode’s MCP vs CLI battle: tools pin runtime, tokens drop from 150K to 2K
Crypto Wrench Attacks Rise 41% in 2026, Targeting Family Members
Over 400 cases of “AI harm,” study reveals that overreliance on artificial intelligence can lead to the development of persecutory delusions