-
Threat actors are increasingly using ClickFix social-engineering lures and search-engine malvertising to deploy MacSync Stealer, a macOS-focused information stealer and remote-access staging framework sold through a malware-as-a-service model. The camp…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Anthropic has enhanced Claude’s desktop automation capabilities, enabling the AI assistant to operate directly on macOS and Windows computers through Claude Cowork and Claude Code. When this feature is enabled, Claude can navigate a visible scree…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
AmnesiaStealer, a multi-stage macOS infostealer written in Rust that moves beyond conventional credential theft by giving attackers covert, interactive control over a victim’s authenticated Chromium browser sessions. The malware is being distributed th…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A macOS-focused ClickFix campaign is abusing Polygon smart contracts to conceal its live command-and-control infrastructure while deploying an Atomic macOS Stealer (AMOS) variant, a persistent backdoor, and an XMRig cryptominer. The operation combines …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
MacSync Stealer is expanding its macOS-focused theft operation through a rotating network of more than 30 domains, using stable execution and network patterns to steal credentials, browser data, cloud access keys, SSH material, and sensitive user files…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A Google-sponsored search result for Claude installation instructions is being used to deliver a sophisticated macOS stealer and remote-access trojan (RAT) named MacSync. The campaign abuses a legitimate Claude shared-conversation page on the claude.ai…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A newly identified macOS infostealer, named AmnesiaStealer, targets users via ClickFix social-engineering campaigns that impersonate GitHub download pages. This malware combines various malicious features, including password theft, browser data collect…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A macOS Keychain implementation weakness in Anthropic’s Claude Code CLI could allow any process running as the logged-in user including a Claude Code-spawned child process to retrieve the tool’s OAuth credential bundle silently. The issue underscores h…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A recently disclosed privilege-related vulnerability in the Common UNIX Printing System (CUPS) on macOS could allow an unprivileged local user to create attacker-controlled files in arbitrary locations outside the protection of System Integrity Protect…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
macOS users are facing a new, highly polished ClickFix campaign that abuses fake CAPTCHAs to execute Terminal commands, silently deploy Atomic macOS Stealer (AMOS), and systematically loot crypto wallets and browser‑stored credentials. This evolution o…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


