Hackers Use ClickFix Lures to Deploy MacSync Stealer and Bypass macOS Security.

Published September 10, 2026

Attackers trick macOS users into running malicious Terminal commands through fake software updates or browser ads. This steals personal data and can let attackers control your Mac remotely.

Report priority
Medium
Targets
macOS

How it works

  • Attackers send fake pop-up ads or fake software update prompts on websites.
  • These ads trick users into opening a Terminal window and pasting a command.
  • The command downloads and runs MacSync Stealer malware, which steals passwords, browser data, and other sensitive information.
  • It also lets attackers take control of the infected Mac remotely.
  • No macOS security flaw is needed, just user trust.

What to do

If you use macOS and saw a fake software update prompt or browser ad asking you to open Terminal and paste a command, check your Terminal history for unfamiliar commands or look for unexpected files in ~/Downloads or ~/Library/Application Support. If you pasted anything, immediately restart your Mac in Safe Mode (hold Shift at startup) to prevent the malware from running.

Then, scan your system with a trusted antivirus like Malwarebytes or Xcode's built-in tools. Update macOS to the latest version and avoid clicking unexpected prompts or ads. If infected, reset your passwords for all accounts and enable two-factor authentication.

Technical details

A user visits a legitimate-looking website that shows a fake Chrome update prompt. The prompt says the browser is outdated and needs a quick fix. When the user clicks 'Update,' they're taken to a fake Terminal window with a command to paste. After pasting, MacSync Stealer downloads and starts stealing their data.

A new campaign uses ClickFix social-engineering lures and search-engine malvertising to distribute MacSync Stealer, a macOS-focused information stealer and remote-access framework sold as malware-as-a-service. Attackers bypass macOS security by tricking victims into manually executing attacker-controlled Terminal commands, rather than relying on file-based exploits. The campaign does not exploit macOS vulnerabilities but instead manipulates user trust to deploy the malware.