Reverse Engineering the Six Stages of MacSync Stealer and RAT

Imported from official source

Cybersecurity Classified by Officially

Huntress recently investigated an incident where the victim searched Google for how to install Claude on a Mac, clicked a sponsored result, and landed on a weaponised claude.ai/share conversation dressed up as an Apple Support install guide. It told them to open Terminal and paste a single curl command. 

MacSync is a six-stage kill chain, not a smash-and-grab. The components are a thin zsh loader, a server-side AppleScript stealer that keeps the valuable logic off the endpoint and behind an api-key gate, a native Mach-O RAT for hands-on access, a separately signed helper built to steal a single TCC permission (Screen Recording), and a set of wallet-app trojans. Each stage sets up the ones that follow.

The malware's end goal was to steal everything it could. MacSync takes the full stealer haul, browser cookies and logins, keychain secrets, a confirmed account password, Telegram sessions, SSH and cloud keys, but the weight of the kit sits on wallets: roughly 60 wallet browser extensions, 21 desktop wallet apps, and three trojanised hardware wallet companion apps are designed to continuously phish recovery phases. 

The operation spans three separate infrastructure tiers: Cloudflare-fronted delivery (agenticsora[.]com in this case and malwareaudit[.]com in a second Huntress incident running the same chain), an operator IP recorded in the stealer's beacon (103.216.221[.]95), and a dedicated raw-IP TLS channel for the RAT (85.206.161[.]241:8443).

Acknowledgments: Special thanks to Ryan Dowd for his contributions to this investigation and write-up.

This is an extract. The publication continues at the source.

Read the original at the source: https://www.huntress.com/blog/macsync-stealer-rat-reverse-engineering

Officially imported this from Huntress’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
Huntress — imported from official source
Official source
https://www.huntress.com/blog/rss.xml RSS
Imported
September 20, 2026 19:55
Versions
1 recorded
Identity
https://www.huntress.com/blog/macsync-stealer-rat-reverse-engineering

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.