Skip to content

The digital town square for the concert band community.

Connect with local ensembles, trade repertoire insights, and keep the pulse of the wind band world.

  • 0 Votes
    1 Posts
    0 Views
    OTX BotT
    Reverse Engineering the Six Stages of MacSync Stealer and RATMacSync is a sophisticated six-stage macOS attack chain initiated when victims search for Claude installation instructions, click malicious Google Ads, and reach weaponized claude.ai/share conversations posing as Apple Support guides. The victim pastes a curl command that deploys a zsh loader, server-side AppleScript stealer, native Mach-O RAT, TCC permission-stealing helper, and wallet trojans. The operation steals browser credentials, keychain secrets, confirmed account passwords, Telegram sessions, SSH keys, and cloud credentials, but focuses heavily on cryptocurrency with approximately 60 wallet browser extensions, 21 desktop apps, and three trojanized hardware wallet companions designed to continuously phish recovery phrases. Infrastructure spans Cloudflare-fronted delivery domains (agenticsora[.]com, malwareaudit[.]com), an operator IP (103.216.221[.]95), dedicated RAT C2 (85.206.161[.]241:8443), and seed-phrase drop domains. The malware persists via LaunchAgents masquerading as legitimate updater se...Pulse ID: 6a6a47bf77b7d1fa679717d8Pulse Link: https://otx.alienvault.com/pulse/6a6a47bf77b7d1fa679717d8 Pulse Author: AlienVaultCreated: 2026-07-29 18:34:39Be advised, this data is unverified and should be considered preliminary. Always do further verification.#Browser #Cloud #CyberSecurity #Google #GoogleAds #ICS #InfoSec #Mac #MacOS #Malware #OTX #OpenThreatExchange #Password #Passwords #RAT #SSH #Telegram #Trojan #Word #bot #cryptocurrency #AlienVault