#malwareasaservice — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #malwareasaservice, aggregated by home.social.
-
MacSync: The Evasive macOS Stealer Exploiting ClickFix Lures
MacSync Stealer is a macOS information stealer and remote-access stager delivered through ClickFix social engineering and malvertising campaigns. Operating under a malware-as-a-service model, it employs sophisticated evasion techniques including process daemonization, single-byte XOR obfuscation, and in-memory AppleScript execution to bypass Apple Gatekeeper, XProtect, and EDR solutions. The malware exfiltrates credentials, browser data, cryptocurrency wallets, and SSH keys through fault-tolerant 10MB chunked uploads to command-and-control infrastructure. MacSync targets professionals in software engineering, cryptocurrency, fintech, and corporate environments across North America, Europe, and Asia-Pacific regions, with campaigns impersonating legitimate services like Google Meet, Claude AI, Docker, and TradingView to trick victims into executing malicious Terminal commands.
Pulse ID: 6a9fff8d4e576223ee6f9b4e
Pulse Link: https://otx.alienvault.com/pulse/6a9fff8d4e576223ee6f9b4e
Pulse Author: AlienVault
Created: 2026-09-08 12:29:01Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #Browser #CyberSecurity #Docker #EDR #Europe #Google #GoogleMeet #InfoSec #Mac #MacOS #Malvertising #Malware #MalwareAsAService #NorthAmerica #OTX #OpenThreatExchange #RAT #SSH #ScriptExecution #SocialEngineering #bot #cryptocurrency #AlienVault
-
MacSync: The Evasive macOS Stealer Exploiting ClickFix Lures
MacSync Stealer is a macOS information stealer and remote-access stager delivered through ClickFix social engineering and malvertising campaigns. Operating under a malware-as-a-service model, it employs sophisticated evasion techniques including process daemonization, single-byte XOR obfuscation, and in-memory AppleScript execution to bypass Apple Gatekeeper, XProtect, and EDR solutions. The malware exfiltrates credentials, browser data, cryptocurrency wallets, and SSH keys through fault-tolerant 10MB chunked uploads to command-and-control infrastructure. MacSync targets professionals in software engineering, cryptocurrency, fintech, and corporate environments across North America, Europe, and Asia-Pacific regions, with campaigns impersonating legitimate services like Google Meet, Claude AI, Docker, and TradingView to trick victims into executing malicious Terminal commands.
Pulse ID: 6a9fff8d4e576223ee6f9b4e
Pulse Link: https://otx.alienvault.com/pulse/6a9fff8d4e576223ee6f9b4e
Pulse Author: AlienVault
Created: 2026-09-08 12:29:01Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #Browser #CyberSecurity #Docker #EDR #Europe #Google #GoogleMeet #InfoSec #Mac #MacOS #Malvertising #Malware #MalwareAsAService #NorthAmerica #OTX #OpenThreatExchange #RAT #SSH #ScriptExecution #SocialEngineering #bot #cryptocurrency #AlienVault
-
MacSync: The Evasive macOS Stealer Exploiting ClickFix Lures
MacSync Stealer is a macOS information stealer and remote-access stager delivered through ClickFix social engineering and malvertising campaigns. Operating under a malware-as-a-service model, it employs sophisticated evasion techniques including process daemonization, single-byte XOR obfuscation, and in-memory AppleScript execution to bypass Apple Gatekeeper, XProtect, and EDR solutions. The malware exfiltrates credentials, browser data, cryptocurrency wallets, and SSH keys through fault-tolerant 10MB chunked uploads to command-and-control infrastructure. MacSync targets professionals in software engineering, cryptocurrency, fintech, and corporate environments across North America, Europe, and Asia-Pacific regions, with campaigns impersonating legitimate services like Google Meet, Claude AI, Docker, and TradingView to trick victims into executing malicious Terminal commands.
Pulse ID: 6a9fff8d4e576223ee6f9b4e
Pulse Link: https://otx.alienvault.com/pulse/6a9fff8d4e576223ee6f9b4e
Pulse Author: AlienVault
Created: 2026-09-08 12:29:01Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #Browser #CyberSecurity #Docker #EDR #Europe #Google #GoogleMeet #InfoSec #Mac #MacOS #Malvertising #Malware #MalwareAsAService #NorthAmerica #OTX #OpenThreatExchange #RAT #SSH #ScriptExecution #SocialEngineering #bot #cryptocurrency #AlienVault
-
MacSync: The Evasive macOS Stealer Exploiting ClickFix Lures
MacSync Stealer is a macOS information stealer and remote-access stager delivered through ClickFix social engineering and malvertising campaigns. Operating under a malware-as-a-service model, it employs sophisticated evasion techniques including process daemonization, single-byte XOR obfuscation, and in-memory AppleScript execution to bypass Apple Gatekeeper, XProtect, and EDR solutions. The malware exfiltrates credentials, browser data, cryptocurrency wallets, and SSH keys through fault-tolerant 10MB chunked uploads to command-and-control infrastructure. MacSync targets professionals in software engineering, cryptocurrency, fintech, and corporate environments across North America, Europe, and Asia-Pacific regions, with campaigns impersonating legitimate services like Google Meet, Claude AI, Docker, and TradingView to trick victims into executing malicious Terminal commands.
Pulse ID: 6a9fff8d4e576223ee6f9b4e
Pulse Link: https://otx.alienvault.com/pulse/6a9fff8d4e576223ee6f9b4e
Pulse Author: AlienVault
Created: 2026-09-08 12:29:01Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #Browser #CyberSecurity #Docker #EDR #Europe #Google #GoogleMeet #InfoSec #Mac #MacOS #Malvertising #Malware #MalwareAsAService #NorthAmerica #OTX #OpenThreatExchange #RAT #SSH #ScriptExecution #SocialEngineering #bot #cryptocurrency #AlienVault
-
MacSync: The Evasive macOS Stealer Exploiting ClickFix Lures
MacSync Stealer is a macOS information stealer and remote-access stager delivered through ClickFix social engineering and malvertising campaigns. Operating under a malware-as-a-service model, it employs sophisticated evasion techniques including process daemonization, single-byte XOR obfuscation, and in-memory AppleScript execution to bypass Apple Gatekeeper, XProtect, and EDR solutions. The malware exfiltrates credentials, browser data, cryptocurrency wallets, and SSH keys through fault-tolerant 10MB chunked uploads to command-and-control infrastructure. MacSync targets professionals in software engineering, cryptocurrency, fintech, and corporate environments across North America, Europe, and Asia-Pacific regions, with campaigns impersonating legitimate services like Google Meet, Claude AI, Docker, and TradingView to trick victims into executing malicious Terminal commands.
Pulse ID: 6a9fff8d4e576223ee6f9b4e
Pulse Link: https://otx.alienvault.com/pulse/6a9fff8d4e576223ee6f9b4e
Pulse Author: AlienVault
Created: 2026-09-08 12:29:01Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #Browser #CyberSecurity #Docker #EDR #Europe #Google #GoogleMeet #InfoSec #Mac #MacOS #Malvertising #Malware #MalwareAsAService #NorthAmerica #OTX #OpenThreatExchange #RAT #SSH #ScriptExecution #SocialEngineering #bot #cryptocurrency #AlienVault
-
Octagon: A New Android Bot Targeting Crypto Wallets and Banking Apps
In June 2026, a previously undocumented Android fraud bot called Octagon was identified, sold as malware-as-a-service by Russian-speaking actor AndroidKitKat for $1,400 monthly. The malware employs accessibility overlays, hidden VNC, SMS interception, unlock-pattern capture, and balance reading capabilities to target cryptocurrency wallets, exchanges, and banking applications. Distributed through sideloaded APKs with Restricted Settings bypass, Octagon connects infected devices to a Windows command-and-control panel where operators monitor applications, read screens, and control devices remotely. The malware maintains persistence through multiple mechanisms while appearing benign to security scans. Three APK samples were recovered, including deployments using Lifted Dreams game and Bahrain government lures. The malware captures credentials through HTML WebView overlays targeting Trust Wallet, Binance, MEXC, MetaMask, and messaging apps like Telegram and WhatsApp, enabling cryptocurrency theft and account t...
Pulse ID: 6a8474eb4f130dfa41887e40
Pulse Link: https://otx.alienvault.com/pulse/6a8474eb4f130dfa41887e40
Pulse Author: AlienVault
Created: 2026-08-18 15:06:19Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#APK #Android #Bank #Binance #CyberSecurity #Government #HTML #InfoSec #Malware #MalwareAsAService #OTX #OpenThreatExchange #RAT #RCE #Russia #Rust #SMS #Telegram #VNC #WhatsApp #Windows #bot #cryptocurrency #AlienVault