Gate News message, April 22 — SlowMist has issued a threat alert regarding an active macOS information stealer malware called MacSync Stealer (v1.1.2). According to SlowMist’s MistEye threat intelligence platform, the malware targets macOS users and can steal cryptocurrency wallets, browser credentials, system keychains, and infrastructure keys (SSH, AWS, K8s). The malware also uses spoofed AppleScript system dialogs to trick users into entering their login passwords, then displays fake “unsupported” error messages.
SlowMist has shared relevant indicators of compromise (IOCs) with its customers and advises users to avoid executing unverified macOS scripts and remain alert to unusual system password prompts.
Related News
Misty 23pds Alert: Lazarus Group releases a new macOS toolkit targeting cryptocurrencies
CometBFT zero-day vulnerability exposed, $8.0 billion Cosmos network nodes face a risk of permanent lockup
Arbitrum emergency freezes KelpDAO hacker’s 30,766 ETH