Related Threat Clusters
-
Slovakia Discovers Russian Backdoor in Traffic Speed Cameras
Slovakia's national security service NBU has issued a security alert regarding NERO R-ONE high-speed traffic cameras, which were found to contain a backdoor allowing access via SMS from hardcoded Russian phone numbers.…
4 articles · Updated August 19, 2026 -
Malicious Ads Target Homebrew Users with MacSync Stealer Malware
Cybercriminals are exploiting Google Ads to promote a fake Homebrew page that installs the MacSync infostealer malware, as reported by security researchers at the SANS Internet Storm Center. This campaign was first…
4 articles · Updated May 4, 2026 -
Trojan Malware Surge and Outdated Software Threaten Mac Security
Recent reports from Jamf indicate a dramatic rise in trojan malware, which now accounts for over 50% of all malware detections on Macs, with Atomic Stealer being the most prevalent variant. The malware's dominance…
6 articles · Updated April 8, 2026 -
MacSync Infostealer Exploits Google Search for Claude Installation
A malvertising campaign has emerged, using Google search results for Claude installation to deliver a macOS infostealer named MacSync. Victims are misled to a legitimate claude.ai shared conversation page, where they…
2 articles · Updated August 19, 2026 -
MacSync Stealer Targets macOS via Malicious Google Ads Campaign
The MacSync Stealer, a newly identified macOS infostealer, is being distributed through a sophisticated malvertising campaign on Google Ads that mimics Anthropic’s Claude Code CLI. Security researchers from Beezlebub…
9 articles · Updated July 1, 2026 -
Microsoft Identifies Over 30 Domains Linked to MacSync Stealer Malware
Microsoft has linked more than 30 rotating domains to the MacSync Stealer, a malware targeting macOS systems. This infrastructure supports various malicious activities, including credential theft and data exfiltration.…
4 articles · Updated August 19, 2026 -
New MacSync Malware Exploits Apple Notarization to Steal User Credentials
A new variant of the MacSync stealer malware has been identified, exploiting Apple's notarization process to bypass security measures on macOS devices. This malware poses a risk to sensitive user data by disguising…
16 articles · Updated December 22, 2025 -
AppleScript Exploited for Malware Distribution on macOS
Hackers are using AppleScript files to deliver malware disguised as legitimate software updates for Zoom, Microsoft Teams, and Chrome on macOS. This method has emerged as a new attack vector following Apple's removal of…
1 article · Updated November 12, 2025 -
Hackers Use AppleScript to Disguise macOS Malware as Legitimate Updates
Cybercriminals are leveraging AppleScript files to distribute malware disguised as legitimate updates for applications like Zoom and Microsoft Teams. This new attack vector allows them to bypass Apple's Gatekeeper…
2 articles · Updated November 12, 2025
Recent Intelligence Reports
- Risky Bulletin: Slovakia finds Russian backdoor in traffic speed cameras — News.Risky.Biz · August 19, 2026
- Microsoft Links 30+ Domains to MacSync Stealer’s Credential-Theft and Data — Gbhackers · August 19, 2026
- Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure — Thehackernews · August 19, 2026
- MacSync Stealer: How a Google Search for Claude Led to a macOS Infostealer — Huntress · August 17, 2026
- A Weaponized Google Ad Install Malicious Claude Code to Hijack Entire macOS — Cybersecuritynews · July 1, 2026
- MacSync Stealer Hijacks macOS via Fake Claude Code Google Ads — Gbhackers · July 1, 2026
- Duncan said in the report — isc.sans.edu · May 4, 2026
- Hackers replace top Google result for Homebrew with sponsored MacOS malware — Cybernews · May 4, 2026