Upcoming Webinar

Aug 11, 2026
1:00PM (ET) | 10:00AM (PT)
60
minutes

Tradecraft Tuesday | Fake Claude install guide, real macOS stealer

A user searched Google for how to install Claude Code on a Mac, clicked a sponsored ad, and landed on a genuine claude.ai share page badged "Shared by Apple Support." It told them to open Terminal and paste one curl command. That command was MacSync, a six-stage macOS stealer and RAT.

The victim pulled the host offline before we could image it, so nothing was left on disk. We rebuilt the loader's request, spoofed the User-Agent, and included the static API key, then pulled every stage directly from the attacker's delivery servers.

We'll walk the chain in the order it runs. The loader is a thin zsh script. It drops an AppleScript stealer that the operator keeps server-side behind an API-key gate, so the valuable logic never touches the endpoint. Next comes a fake Full Disk Access prompt, followed by a password box checked live against dscl . authonly, which means the operator only ever walks away with a working credential. A C++ Mach-O RAT follows, along with a signed helper named "Screen Recording" built to farm one TCC grant. The last stage swaps in trojanized Ledger and Trezor apps to phish the recovery phrase.

Every stage in this chain runs toward one target: the wallet.

Reserve Your Spot
By submitting this form, you accept our Terms of Service & Privacy Policy

Speakers

Josh Kiriakoff

Security Operations Analyst

LinkedIn icon

Ryan Dowd

Principal Security Operations Center Analyst