A fake Claude Code ad tells Mac devs to paste a Terminal command. It installs AMOS Stealer. https://intel.threadlinqs.com/threat/TL-2026-2916 #ThreatIntel #AMOS #MacSync #Atomic

A fake Claude Code ad tells Mac devs to paste a Terminal command. It installs AMOS Stealer. https://intel.threadlinqs.com/threat/TL-2026-2916 #ThreatIntel #AMOS #MacSync #Atomic
A new MacSync macOS infostealer spreads via fake apps. Learn how the MacSync macOS infostealer abuses iCloud to compromise Apple systems.
#MacSync #macOSMalware #Infostealer #CyberSecurity #Kaspersky
Digital security, the hottest front shifts to MacSync and RemControl
Sicurezza digitale, il fronte più caldo passa da MacSync e RemControl
A fake crypto wallet app hides its C2 commands inside a public iCloud calendar event. https://intel.threadlinqs.com/threat/TL-2026-2723 #ThreatIntel #MacSync #http #Toria
A newly discovered MacSync malware campaign is using public iCloud calendar invites to deploy backdoors on macOS. Learn how to protect your device.
https://macbreeze.com/macsync-malware-icloud-calendar-macos/
📢 MacSync : nouvelle version du stealer macOS avec chaîne d'infection binaire et backdoor
Cet article présente une analyse technique approfondie d'une nouvelle variante du stealer macOS MacSync, détectée pour la première fois dans la…
🟢 vérification factuelle haute
#MacSync #backdoor #Cyberveille
Kaspersky found MacSync malware hiding commands in an iCloud calendar, using a fake Toria wallet app and a Finder impostor to steal passwords, crypto data, files, and developer info from Macs. #MacSync #Kaspersky #Toria
Researchers highlight MacSync malware, caution against its use of iCloud calendar events to propagate itself in the wild
www.powerpage.org/researchers-...
#Apple #malware #macOS #Mac #MacSync #hack #privacy #security #iCloud #calendar #calendarevents #datatheft #credentials
Malware hides in iCloud calendars to deliver payloads. Monitor public calendar events! #MacSync #Cybersecurity #Mal
MacSync hides zsh commands in iCloud calendar events to drop a Finder-disguised backdoor on macOS. https://intel.threadlinqs.com/threat/TL-2026-2641 #ThreatIntel #MacSync #sn_relay #AMOS
~Kaspersky~
MacSync now uses binary droppers and Swift/Objective-C payloads to steal developer and crypto data on macOS.
-
IOCs: docsend[.]appstore[.]com[.]mx, toria[.]apple03cloudstore[.]com, toria[.]app
-
#MacSync #Malware #ThreatIntel
MacSync serves its stage-two from a public iCloud calendar - then drains your Keychain and wallets. https://intel.threadlinqs.com/threat/TL-2026-2637 #ThreatIntel #AMOS #MacSync #Macc
MacSync si evolve e prende di mira i Mac: ruba password, dati Telegram e criptovalute #Android #browser #computer #criptovalute #hacker #icloud #Kaspersky #mac #MacOS #macsync #malware #telegram 🔗 https://guruhitech.com/macsync-si-evolve-e-prende-di-mira-i-mac-ruba-password-dati-telegram-e-crip...
HBO Max's Reddit account got hijacked to push ClickFix ads that hack you via copy-paste. https://intel.threadlinqs.com/threat/TL-2026-2506 #ThreatIntel #MacSync #AMOS #InstallFix
Beware: fake ChatGPT/Claude installers delivering MacSync malware steal passwords & wallets. #MacSync #Malware #AI #CyberSecurity #PasswordStealer #MacOS https://thedailytechfeed.com/fake-claude-chatgpt-installers-deliver-mac-password-stealer-macsync/
MacSync Stealer poses as Claude AI, tricks you into pasting one Terminal command, then drains your Mac. https://intel.threadlinqs.com/threat/TL-2026-2434 #ThreatIntel #MacSync #Macc #ClickFix