MacOS isn’t too much of a safe haven than Windows as infostealers come for Apple computers

Date:

Share:


I used to be of the opinion that MacBooks are relatively safer than other laptops, but I have been proven wrong. Embarrassingly and demonstrably wrong. A new report from Sophos X-Ops has spared no effort in rubbing my nose in it. 

Researchers at the firm tracked three separate attack campaigns between November 2025 and February 2026, all of which targeted macOS users with something called the MacSync infostealer. For those catching up — it’s a type of malware that quietly rifles through your passwords and saved credentials, acting like a digital pickpocket. 

So, how does it actually work?

The malware used a delivery method called ClickFix, which requires minimal technical effort. It just needs the victims to copy and paste a command into their Mac’s Terminal (designed to run and execute text-based commands) and press enter on the keyboard.

First, bad actors used fake OpenAI download pages, which were circulated via sponsored ads on Google (sitting right above the legitimate link). Then, they got even more creative: attackers started sharing rear ChatGPT shared conversations disguised as “helpful Mac guides.”

These guides routed users into fake GitHub pages, which contained carefully created software installation instructions, but in reality, they asked users to copy a terminal command, allowing the ManSync infostealer to work in the background. That’s it; that’s the whole attack. 

How bad did it get?

Sophos has found out that by December 2025 alone, bad actors had routed more than 50,000 clicks on such malicious domains. A “click” means that someone copied the malicious terminal command, but not necessarily that the malware successfully installed; the actual infection count could be lower. 

The developers put another spin on their attacking method in February 2026, allowing it to run silently in the background, bypassing the competent macOS security tools such as Gatekeeper and XProtect. It can, in a very real way, patch your ledger crypto wallet’s 24-word master key. 

The firm reports that infection clusters were active in key markets, including parts of North and South America and India, as recently as weeks before they published the article (by the end of the beginning of March, possibly). 

Moreover, the notion that “Macs are safe,” is at least, for the time being, not true. As AI platforms grow in popularity, and, more importantly, gain the trust of millions of users, bad actors are coming up with new ways to use the LLMs-driven tools to their advantage. For now, I’d advise you to not paste any text-based command into your Mac’s Terminal.



Source link

━ more like this

Nothing updates its AI app with semantic search and a new way to track events

In the mad dash many companies have made to incorporate AI features into their phones, Nothing arrived at one of the better ideas...

Prime Video’s ad free subscription becomes Prime Video Ultra for $4.99 a month

Amazon is updating its ad-free streaming offering by introducing Prime Video Ultra, a new subscription tier designed for viewers who want to watch...

Peacock app is getting vertical NBA videos and a Jeopardy game, too

Peacock is adding several AI-powered features to its mobile app, including vertical NBA broadcasts, a personalized Bravo video hub, and an in-app Jeopardy...

Samsung’s new Galaxy Z Flip 8 might be a battery bummer

Samsung’s next clamshell folding phone could end up being a disappointment in the battery department. Despite the Galaxy Z Flip 7 seeing a...

You’ll now have to fork out for an additional subscription if you want to watch 4K content on Prime Video

Amazon is the price of its ad-free Prime Video subscription and locking 4K UHD streaming behind this new tier. Starting April 10...
spot_img