Digitaltrends
Rise of Mac Infostealers: New Malware Targets macOS Users
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Recent reports indicate a surge in infostealer malware targeting macOS users, specifically the MacSync infostealer. Sophos X-Ops tracked three attack campaigns from November 2025 to February 2026, revealing that attackers utilized fake OpenAI download pages and misleading ChatGPT guides to deliver the malware. The attack method involved users copying a malicious command into their Mac's Terminal, enabling the malware to operate undetected. By December 2025, over 50,000 clicks on malicious domains were recorded, indicating significant interest in the attacks. The malware can bypass macOS security tools like Gatekeeper and XProtect, posing a serious risk to users' sensitive information, including cryptocurrency wallet keys. The campaigns were active in key markets, including North and South America and India, as of early March 2026. Users are advised to avoid pasting commands into their Terminal to mitigate risks.
Key Points: • MacSync infostealer targets macOS users through deceptive methods. • Over 50,000 clicks on malicious domains indicate widespread interest. • Malware can bypass macOS security tools, risking sensitive data.