#malwareasaservice — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #malwareasaservice, aggregated by home.social.
-
MacSync: The Evasive macOS Stealer Exploiting ClickFix Lures
MacSync Stealer is a macOS information stealer and remote-access stager delivered through ClickFix social engineering and malvertising campaigns. Operating under a malware-as-a-service model, it employs sophisticated evasion techniques including process daemonization, single-byte XOR obfuscation, and in-memory AppleScript execution to bypass Apple Gatekeeper, XProtect, and EDR solutions. The malware exfiltrates credentials, browser data, cryptocurrency wallets, and SSH keys through fault-tolerant 10MB chunked uploads to command-and-control infrastructure. MacSync targets professionals in software engineering, cryptocurrency, fintech, and corporate environments across North America, Europe, and Asia-Pacific regions, with campaigns impersonating legitimate services like Google Meet, Claude AI, Docker, and TradingView to trick victims into executing malicious Terminal commands.
Pulse ID: 6a9fff8d4e576223ee6f9b4e
Pulse Link: https://otx.alienvault.com/pulse/6a9fff8d4e576223ee6f9b4e
Pulse Author: AlienVault
Created: 2026-09-08 12:29:01Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #Browser #CyberSecurity #Docker #EDR #Europe #Google #GoogleMeet #InfoSec #Mac #MacOS #Malvertising #Malware #MalwareAsAService #NorthAmerica #OTX #OpenThreatExchange #RAT #SSH #ScriptExecution #SocialEngineering #bot #cryptocurrency #AlienVault
-
MacSync: The Evasive macOS Stealer Exploiting ClickFix Lures
MacSync Stealer is a macOS information stealer and remote-access stager delivered through ClickFix social engineering and malvertising campaigns. Operating under a malware-as-a-service model, it employs sophisticated evasion techniques including process daemonization, single-byte XOR obfuscation, and in-memory AppleScript execution to bypass Apple Gatekeeper, XProtect, and EDR solutions. The malware exfiltrates credentials, browser data, cryptocurrency wallets, and SSH keys through fault-tolerant 10MB chunked uploads to command-and-control infrastructure. MacSync targets professionals in software engineering, cryptocurrency, fintech, and corporate environments across North America, Europe, and Asia-Pacific regions, with campaigns impersonating legitimate services like Google Meet, Claude AI, Docker, and TradingView to trick victims into executing malicious Terminal commands.
Pulse ID: 6a9fff8d4e576223ee6f9b4e
Pulse Link: https://otx.alienvault.com/pulse/6a9fff8d4e576223ee6f9b4e
Pulse Author: AlienVault
Created: 2026-09-08 12:29:01Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #Browser #CyberSecurity #Docker #EDR #Europe #Google #GoogleMeet #InfoSec #Mac #MacOS #Malvertising #Malware #MalwareAsAService #NorthAmerica #OTX #OpenThreatExchange #RAT #SSH #ScriptExecution #SocialEngineering #bot #cryptocurrency #AlienVault
-
MacSync: The Evasive macOS Stealer Exploiting ClickFix Lures
MacSync Stealer is a macOS information stealer and remote-access stager delivered through ClickFix social engineering and malvertising campaigns. Operating under a malware-as-a-service model, it employs sophisticated evasion techniques including process daemonization, single-byte XOR obfuscation, and in-memory AppleScript execution to bypass Apple Gatekeeper, XProtect, and EDR solutions. The malware exfiltrates credentials, browser data, cryptocurrency wallets, and SSH keys through fault-tolerant 10MB chunked uploads to command-and-control infrastructure. MacSync targets professionals in software engineering, cryptocurrency, fintech, and corporate environments across North America, Europe, and Asia-Pacific regions, with campaigns impersonating legitimate services like Google Meet, Claude AI, Docker, and TradingView to trick victims into executing malicious Terminal commands.
Pulse ID: 6a9fff8d4e576223ee6f9b4e
Pulse Link: https://otx.alienvault.com/pulse/6a9fff8d4e576223ee6f9b4e
Pulse Author: AlienVault
Created: 2026-09-08 12:29:01Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #Browser #CyberSecurity #Docker #EDR #Europe #Google #GoogleMeet #InfoSec #Mac #MacOS #Malvertising #Malware #MalwareAsAService #NorthAmerica #OTX #OpenThreatExchange #RAT #SSH #ScriptExecution #SocialEngineering #bot #cryptocurrency #AlienVault
-
MacSync: The Evasive macOS Stealer Exploiting ClickFix Lures
MacSync Stealer is a macOS information stealer and remote-access stager delivered through ClickFix social engineering and malvertising campaigns. Operating under a malware-as-a-service model, it employs sophisticated evasion techniques including process daemonization, single-byte XOR obfuscation, and in-memory AppleScript execution to bypass Apple Gatekeeper, XProtect, and EDR solutions. The malware exfiltrates credentials, browser data, cryptocurrency wallets, and SSH keys through fault-tolerant 10MB chunked uploads to command-and-control infrastructure. MacSync targets professionals in software engineering, cryptocurrency, fintech, and corporate environments across North America, Europe, and Asia-Pacific regions, with campaigns impersonating legitimate services like Google Meet, Claude AI, Docker, and TradingView to trick victims into executing malicious Terminal commands.
Pulse ID: 6a9fff8d4e576223ee6f9b4e
Pulse Link: https://otx.alienvault.com/pulse/6a9fff8d4e576223ee6f9b4e
Pulse Author: AlienVault
Created: 2026-09-08 12:29:01Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #Browser #CyberSecurity #Docker #EDR #Europe #Google #GoogleMeet #InfoSec #Mac #MacOS #Malvertising #Malware #MalwareAsAService #NorthAmerica #OTX #OpenThreatExchange #RAT #SSH #ScriptExecution #SocialEngineering #bot #cryptocurrency #AlienVault
-
MacSync: The Evasive macOS Stealer Exploiting ClickFix Lures
MacSync Stealer is a macOS information stealer and remote-access stager delivered through ClickFix social engineering and malvertising campaigns. Operating under a malware-as-a-service model, it employs sophisticated evasion techniques including process daemonization, single-byte XOR obfuscation, and in-memory AppleScript execution to bypass Apple Gatekeeper, XProtect, and EDR solutions. The malware exfiltrates credentials, browser data, cryptocurrency wallets, and SSH keys through fault-tolerant 10MB chunked uploads to command-and-control infrastructure. MacSync targets professionals in software engineering, cryptocurrency, fintech, and corporate environments across North America, Europe, and Asia-Pacific regions, with campaigns impersonating legitimate services like Google Meet, Claude AI, Docker, and TradingView to trick victims into executing malicious Terminal commands.
Pulse ID: 6a9fff8d4e576223ee6f9b4e
Pulse Link: https://otx.alienvault.com/pulse/6a9fff8d4e576223ee6f9b4e
Pulse Author: AlienVault
Created: 2026-09-08 12:29:01Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #Browser #CyberSecurity #Docker #EDR #Europe #Google #GoogleMeet #InfoSec #Mac #MacOS #Malvertising #Malware #MalwareAsAService #NorthAmerica #OTX #OpenThreatExchange #RAT #SSH #ScriptExecution #SocialEngineering #bot #cryptocurrency #AlienVault
-
Uncovering StreamRat: From Meta Ads to Full Device Takeover
ThreatFabric researchers discovered StreamRat, a sophisticated Android banking trojan distributed through Meta and TikTok advertisements disguised as a free TV-streaming service targeting Spanish-speaking users. The campaign reached approximately 570,000 potential victims, primarily in Spain. StreamRat employs a two-stage installation process, utilizing a dropper that implements internet-blocking mechanisms via non-functional VPN connections. Once installed, the trojan abuses Accessibility Services and MediaProjection API to provide operators with near-complete device control, featuring VNC and hidden-screen control, UI-tree collection, keylogging, credential-stealing overlays, and screen-blocking capabilities. The malware appears designed as a Malware-as-a-Service offering, with a sophisticated control panel supporting multiple user roles and WebSocket-based C2 communications.
Pulse ID: 6a9826f869eb70a6b15298ec
Pulse Link: https://otx.alienvault.com/pulse/6a9826f869eb70a6b15298ec
Pulse Author: AlienVault
Created: 2026-09-02 13:39:04Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Android #Bank #BankingTrojan #CyberSecurity #InfoSec #Malware #MalwareAsAService #OTX #OpenThreatExchange #RAT #SMS #Spain #ThreatFabric #Trojan #VNC #VPN #bot #AlienVault
-
Hackers Use Fake CAPTCHA to Install Malware That Kills 145 Security Processes
Indicators extracted from public reporting. Source: https://www.esentire.com/blog/malware-as-a-service-cocktail-errtraffic-and-cruciferra-killing-your-edr-since-2025
Pulse ID: 6a87077b82a77bd532367445
Pulse Link: https://otx.alienvault.com/pulse/6a87077b82a77bd532367445
Pulse Author: CyberHunter_NL
Created: 2026-08-20 13:56:11Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CAPTCHA #CyberSecurity #EDR #HTTP #HTTPS #InfoSec #Malware #MalwareAsAService #OTX #OpenThreatExchange #RCE #bot #eSentire #CyberHunter_NL
-
Malware on tap? Atroposia lets even novice hackers rent a toolkit that bypasses Windows defenses, steals credentials, and even targets crypto. How safe are we when cybercrime is just a subscription away?
#atroposia
#malwareasaservice
#cybercrime
#remotetrojan
#credentialtheft