Gate News message, April 22 — SlowMist has issued a threat alert regarding an active macOS information stealer malware called MacSync Stealer (v1.1.2). According to SlowMist's MistEye threat intelligence platform, the malware targets macOS users and can steal cryptocurrency wallets, browser credentials, system keychains, and infrastructure keys (SSH, AWS, K8s). The malware also uses spoofed AppleScript system dialogs to trick users into entering their login passwords, then displays fake "unsupported" error messages.
SlowMist has shared relevant indicators of compromise (IOCs) with its customers and advises users to avoid executing unverified macOS scripts and remain alert to unusual system password prompts.