Something fishy in the /tmp folder
Think your Macs are immune? Here, a busy employee sees a "macOS Protection Service" prompt. It looks official, so they enter their password. Instantly, the MacSync stealer starts to "cook." It harvests Keychain credentials, Chrome cookies, and 200+ crypto wallets, stuffing the data into a local folder aptly named, but incorrectly spelled, “salmonela.”
The attacker might’ve failed their spelling test, but they didn't fail to scrape sensitive data on the device. Huntress saw the mess before the data could be served to the attacker by:
Flagging the suspicious process on the Mac endpoint
The SOC verifying malicious activity
Isolating the host to stop the attack and prevent further compromise