Reverse Engineering the Six Stages of MacSync Stealer and RAT
Cybersecurity Classified by Officially
Huntress recently investigated an incident where the victim searched Google for how to install Claude on a Mac, clicked a sponsored result, and landed on a weaponised claude.ai/share conversation dressed up as an Apple Support install guide. It told them to open Terminal and paste a single curl command.
MacSync is a six-stage kill chain, not a smash-and-grab. The components are a thin zsh loader, a server-side AppleScript stealer that keeps the valuable logic off the endpoint and behind an api-key gate, a native Mach-O RAT for hands-on access, a separately signed helper built to steal a single TCC permission (Screen Recording), and a set of wallet-app trojans. Each stage sets up the ones that follow.
The malware's end goal was to steal everything it could. MacSync takes the full stealer haul, browser cookies and logins, keychain secrets, a confirmed account password, Telegram sessions, SSH and cloud keys, but the weight of the kit sits on wallets: roughly 60 wallet browser extensions, 21 desktop wallet apps, and three trojanised hardware wallet companion apps are designed to continuously phish recovery phases.
The operation spans three separate infrastructure tiers: Cloudflare-fronted delivery (agenticsora[.]com in this case and malwareaudit[.]com in a second Huntress incident running the same chain), an operator IP recorded in the stealer's beacon (103.216.221[.]95), and a dedicated raw-IP TLS channel for the RAT (85.206.161[.]241:8443).
Acknowledgments: Special thanks to Ryan Dowd for his contributions to this investigation and write-up.
This is an extract. The publication continues at the source.
Read the original at the source: https://www.huntress.com/blog/macsync-stealer-rat-reverse-engineering
Officially imported this from Huntress’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- Huntress — imported from official source
- Official source
- https://www.huntress.com/blog/rss.xml RSS
- Imported
- September 20, 2026 19:55
- Versions
- 1 recorded
- Identity
https://www.huntress.com/blog/macsync-stealer-rat-reverse-engineering