Tag: macOS
-
MacSync Stealer RAT Uses Fake Claude Guides to Steal Passwords and Crypto Wallets
A newly disclosed macOS malware campaign dubbed MacSync weaponizes fake Claude AI installation guides to deploy a six-stage stealer and remote access trojan. Documented by Huntress, the kit targets browser credentials, keychain secrets, and cryptocurrency wallets. The attack begins when victims search Google for >>how to install Claude on a Mac<< and click a sponsored…
-
Malvertising-Kampagne täuscht macOS-Nutzern Systemabsturz vor
Eine macOS-Kampagne verleitet Nutzer über eine vermeintlich abstürzende Systemaktualisierung zur Ausführung eines Schadbefehls. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/malvertising-kampagne-macos
-
Google Chrome 151 Patches 370 Vulnerabilities, Including 7 Critical
Google Chrome 151 patches 370 security flaws, including seven Critical vulnerabilities. Users on Windows, macOS, and Linux should update now. The post Google Chrome 151 Patches 370 Vulnerabilities, Including 7 Critical appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-google-chrome-151-370-vulnerabilities/
-
ClickFix Campaign Uses EtherHiding to Hide Malware and Exposes DPRK Wallet Trail
ClickFix-style fake macOS updates are now being weaponized with EtherHiding-backed command”‘and”‘control and a DPRK-linked crypto laundering network, turning a routine search click into a full-stack theft operation spanning browser, endpoint, blockchain, and exchange infrastructure. Instead of traditional web C2, the implant resolves its live command”‘and”‘control endpoints from Ethereum smart contracts, a takedown”‘resistant pattern known as…
-
DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware
Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web pages displaying a full-screen non-existent update sequence to deliver malware as part of a new iteration of the long-running Contagious Interview campaign.The defining aspect of the attack is that bogus macOS software…
-
Fake Claude Code Installer Delivers MacSync macOS Infostealer Through Google Ads
A highly convincing malvertising campaign is targeting macOS users searching for “how to install Claude Code on Mac,” delivering the MacSync infostealer through a trusted-looking workflow that abuses legitimate infrastructure rather than exploiting software vulnerabilities. The attack highlights a growing shift toward trust-based compromise, where attackers weaponize authentic platforms such as Google Ads and claude.ai…
-
macOS Gatekeeper vulnerability allows app replacement
First seen on scworld.com Jump to article: www.scworld.com/brief/macos-gatekeeper-vulnerability-allows-app-replacement
-
Claude Cowork Sandbox Escape Flaw Lets Attackers Access SSH Keys and Cloud Credentials
A newly revealed sandbox escape vulnerability affecting Anthropic’s Claude Cowork could allow untrusted content processed by the AI agent to access sensitive files on a macOS host. This includes SSH private keys, cloud credentials, and other data that are available to the logged-in user. Security researcher Oren Yomtov from Accomplish has named this attack path…
-
Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files
Cybersecurity researchers have uncovered a sandbox escape vulnerability in Anthropic’s Claude Cowork that makes it possible to break out of the confines of a Linux virtual machine (VM) within which the agent runs to read or write files anywhere on the Mac.Accomplish AI, which shared details of the vulnerability with The Hacker News ahead of…
-
Researchers Uncover North Korean ‘ClickFake’ Campaign Targeting Web3 Pros
In a new campaign, North Korean hacking group Famous Chollima targeted crypto professionals through ClickFix lures to deliver Windows and macOS trojans First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/north-korean-clickfake-campaign/
-
DocuSign Phishing Kit Delivers RMM Tools to Windows and macOS
BlueVoyant uncovered a DocuSign phishing campaign delivering legitimate RMM tools to Windows and macOS for persistence. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/docusign-phishing-kit-delivers-rmm-tools-to-windows-and-macos/
-
MacOS malware hijacks Telegram sessions, targets crypto wallets
First seen on scworld.com Jump to article: www.scworld.com/brief/macos-malware-hijacks-telegram-sessions-targets-crypto-wallets
-
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 106
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter CrashStealer: C++ macOS infostealer posing as crash reporter Lucide Proxy: Turning Student Web Proxies into DDoS Bots AsyncAPI npm organization compromised, 2M weekly downloads affected OkoBot: new sophisticated malware framework targets cryptocurrency users […]…
-
New ClickLock macOS malware traps users into revealing login password
A new macOS information-stealing malware dubbed ClickLock terminates all visible processes to force users into entering their system login password. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-clicklock-macos-malware-traps-users-into-revealing-login-password/
-
OnionHop: Tool leitet Daten durch das Tor-Netzwerk
OnionHop für Linux, macOS und Windows ist ein Routing-Manager, der die Daten einzelner oder aller Programme über das Tor-Netzwerk leitet. First seen on tarnkappe.info Jump to article: tarnkappe.info/artikel/it-sicherheit/datenschutz/onionhop-tool-leitet-daten-durch-das-tor-netzwerk-331520.html
-
New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password
ClickLock Stealer, a new macOS infostealer, answers a victim’s refusal by killing their apps on a loop until they hand over the login password. It arrives as a command pasted into Terminal, asks for the password behind a fake system dialog, and when the victim cancels, installs two LaunchAgents and quietly exits.At the next login,…
-
Modular macOS Stealer Uses Kill Loops to Force Password Entry
New ClickLock macOS stealer locked victims out of their own system until they surrendered a password First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/clicklock-macos-stealer-clickfix/
-
Hackers Pair Stolen Wallet Databases With Keychain Passwords for Offline Crypto Theft
A macOS-focused information stealer is combining stolen wallet databases with credentials harvested from the Apple Keychain, browsers, and Apple Notes to conduct offline cryptocurrency theft attempts. Detected by the MistEye security monitoring system, the malware appears designed for broad data collection rather than a single targeted objective. Its collection scope includes macOS Keychain files, Safari…
-
New macOS malware steals passwords by posing as Apple’s crash-reporting tool
Jamf Threat Labs has uncovered a new macOS infostealer named CrashStealer that disguises itself as Apple’s crash-reporting tool to steal passwords, Keychain data, and … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/14/crashstealer-macos-infostealer-password-theft/
-
New MacOS Malware Exploits Legitimate Developer ID to Pose as Apple Crash Reporter
Researchers at Jamf Threat Labs detail CrashStealer, which steals passwords, cryptocurrency wallets and more First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/macos-malware-apple-crash-reporter/
-
CrashStealer: New macOS Infostealer Uses Signed Apps to Evade Gatekeeper
New macOS infostealer CrashStealer uses a signed app to bypass Gatekeeper, steals credentials and wallets, then AES-encrypts stolen data. Jamf Threat Labs first spotted CrashStealer in early May 2026 as a suspicious macOS sample uploaded to VirusTotal. By early July, in-the-wild detections confirmed the malware had moved from development into active deployment. The malware is…
-
New CrashStealer malware poses as Apple crash reporting tool
A new macOS information-stealing malware called CrashStealer pretends to be Apple’s crash-reporting tool to steal credentials, keychain data, and crypto wallets. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-crashstealer-malware-poses-as-apple-crash-reporting-tool/
-
CrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper Checks
Cybersecurity researchers have flagged a new macOS information stealer called CrashStealer that’s capable of harvesting sensitive data from compromised systems.Unlike other information stealers that are built on AppleScript droppers or Objective-C-based wrappers, CrashStealer is implemented in native C++, according to Jamf Threat Labs.”It validates the victim’s login password locally before First seen on thehackernews.com Jump…
-
Google Chrome Update Patches 27 Security Vulnerabilities Including Critical UseFree Flaws
Google has released a critical security update for Chrome, upgrading the Stable channel to version 150.0.7871.114/.115 on Windows and macOS, and to version 150.0.7871.114 on Linux. This update addresses 27 vulnerabilities, including several critical use-after-free flaws that could potentially enable remote code execution. The update will roll out gradually over the coming days and weeks,…
-
macOS is becoming a proving ground for AI agents
Somewhere right now, a Mac Mini is sitting on a shelf doing someone’s chores. Nobody’s watching it. It reads a version number out of Terminal, hops over to Safari, … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/08/macos-ai-agents-automation/
-
New QuimaRAT malware targets Windows, Linux, and macOS via MaaS model
First seen on scworld.com Jump to article: www.scworld.com/brief/new-quimarat-malware-targets-windows-linux-and-macos-via-maas-model
-
Neuer macOS-Infostealer tarnt sich als Maccy-Anwendung
Sicherheitsforscher von Jamf Threat Labs haben eine neue Schadsoftware für macOS entdeckt, die gezielt auf den Diebstahl sensibler Daten ausgelegt ist. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/macos-infostealer-maccy-anwendung
-
New Java-Based QuimaRAT MaaS Built to Run on Windows, Linux, and macOS
Cybersecurity researchers have flagged a novel Java-based remote access trojan (RAT) called QuimaRAT that’s capable of targeting Windows, Linux, and macOS environments.According to LevelBlue, the cross-platform malware is advertised under a malware-as-a-service (MaaS) model, costing anywhere between $150 for one month to $1,200 for lifetime access. Other subscription tiers include $300 for First seen on…

