CVE-2024-55956: n/a
MacSync is a sophisticated six-stage macOS attack chain initiated when victims search for Claude installation instructions, click malicious Google Ads, and reach weaponized claude.ai/share conversations posing as Apple Support guides. The victim pastes a curl command that deploys a zsh loader, server-side AppleScript stealer, native Mach-O RAT, TCC permission-stealing helper, and wallet trojans. The operation steals browser credentials, keychain secrets, confirmed account passwords, Telegram sessions, SSH keys, and cloud credentials, but focuses heavily on cryptocurrency with approximately 60 wallet browser extensions, 21 desktop apps, and three trojanized hardware wallet companions designed to continuously phish recovery phrases. Infrastructure spans Cloudflare-fronted delivery domains (agenticsora[.]com, malwareaudit[.]com), an operator IP (103.216.221[.]95), dedicated RAT C2 (85.206.161[.]241:8443), and seed-phrase drop domains. The malware persists via LaunchAgents masquerading as legitimate updater se...
AI Analysis
Technical Summary
MacSync is a sophisticated six-stage macOS attack chain triggered when users searching for Claude installation instructions are redirected via malicious Google Ads to weaponized claude.ai/share conversation pages posing as Apple Support guides. Victims execute a curl command that installs a multi-component malware suite including a zsh loader, server-side AppleScript stealer, native Mach-O RAT, TCC permission-stealing helper, and cryptocurrency wallet trojans. The operation steals extensive credentials including browser data, keychain secrets, confirmed passwords, Telegram sessions, SSH keys, and cloud credentials, with a particular emphasis on cryptocurrency wallets (60 browser extensions, 21 desktop apps, and 3 trojanized hardware wallet companions). Persistence is achieved through LaunchAgents masquerading as legitimate updaters. The attack infrastructure uses Cloudflare-fronted delivery domains and dedicated RAT command-and-control servers. The vulnerability affects macOS versions prior to 5.8.0.24 and is rated critical with a CVSS 3.1 score of 9.8.
Potential Impact
Successful exploitation results in full compromise of affected macOS systems, including theft of browser credentials, keychain secrets, confirmed account passwords, Telegram sessions, SSH keys, and cloud credentials. The attack heavily targets cryptocurrency assets by phishing recovery phrases from numerous wallet browser extensions, desktop apps, and hardware wallet companions. The malware achieves persistence and stealth, enabling ongoing data exfiltration and remote access via a native Mach-O RAT and other components. This leads to high confidentiality, integrity, and availability impacts.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. In the absence of an official fix, users should avoid executing untrusted curl commands, especially those sourced from unverified websites or ads. Exercise caution when following installation instructions from unofficial sources. Monitor for suspicious LaunchAgents and network connections to known malicious infrastructure domains (agenticsora[.]com, malwareaudit[.]com) and IP addresses (103.216.221.95, 85.206.161.241:8443). Employ endpoint detection tools capable of identifying Mach-O RATs and TCC permission abuse. Follow vendor advisories for updates on patches or official mitigations.
Indicators of Compromise
- cve: CVE-2024-55956
- url: http://com.apple.preference.security?Privacy_AllFiles
- domain: malwareaudit.com
- hash: 9dd465d26c7d86b4a6f514a4b46b2295
- hash: 071bd109208eb1080ef525b5be394244cec467c59ffef5b8782cfb5e4850401d
- hash: 230dff4bf9442a951dcd6898b2110924969a20668c20a43e3ceed6fcef65963e
- hash: 31566a1df7070f30cb990aa5eab310c1d4e0266c8776e9438138e5438ec1cff8
- hash: 3ae26ed89d3a1a140edc89ca78513aba2895789ed0d0f64cad6605b6f2347c7e
- hash: 3db8befc08dc02ab7a76b5193abd81653775e8f3ceac5864c7c2188b2dbd3c54
- hash: 78dea0693ac2d70bdf8be7588667a75910e43fd84397ad484e710e37369a30f7
- hash: 9c09c303fa058c2d3e179969bd58ca5523775ff2d310fb2f8266ac74cb21ee81
- url: http://agenticsora.com/curl/
- url: http://agenticsora.com/dynamic?txd=
- url: http://agenticsora.com/gate?buildtxd=
- url: http://main.sdhomeinspectors.com/modules/wallets
- url: http://main.southcarolinacounselor.com/modules/wallets
- url: https://agenticsora.com/ledger/
- url: https://agenticsora.com/loader/agent/
- url: https://agenticsora.com/loader/capture-agent/
- url: https://main.sdhomeinspectors.com/modules/wallets'
- domain: agenticsora.com
- domain: sdhomeinspectors.com
- domain: sldev.cz
- domain: southcarolinacounselor.com
- domain: main.sdhomeinspectors.com
- domain: main.southcarolinacounselor.com
CVE-2024-55956: n/a
Description
MacSync is a sophisticated six-stage macOS attack chain initiated when victims search for Claude installation instructions, click malicious Google Ads, and reach weaponized claude.ai/share conversations posing as Apple Support guides. The victim pastes a curl command that deploys a zsh loader, server-side AppleScript stealer, native Mach-O RAT, TCC permission-stealing helper, and wallet trojans. The operation steals browser credentials, keychain secrets, confirmed account passwords, Telegram sessions, SSH keys, and cloud credentials, but focuses heavily on cryptocurrency with approximately 60 wallet browser extensions, 21 desktop apps, and three trojanized hardware wallet companions designed to continuously phish recovery phrases. Infrastructure spans Cloudflare-fronted delivery domains (agenticsora[.]com, malwareaudit[.]com), an operator IP (103.216.221[.]95), dedicated RAT C2 (85.206.161[.]241:8443), and seed-phrase drop domains. The malware persists via LaunchAgents masquerading as legitimate updater se...
CVSS v3.1
Score 9.8critical
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
MacSync is a sophisticated six-stage macOS attack chain triggered when users searching for Claude installation instructions are redirected via malicious Google Ads to weaponized claude.ai/share conversation pages posing as Apple Support guides. Victims execute a curl command that installs a multi-component malware suite including a zsh loader, server-side AppleScript stealer, native Mach-O RAT, TCC permission-stealing helper, and cryptocurrency wallet trojans. The operation steals extensive credentials including browser data, keychain secrets, confirmed passwords, Telegram sessions, SSH keys, and cloud credentials, with a particular emphasis on cryptocurrency wallets (60 browser extensions, 21 desktop apps, and 3 trojanized hardware wallet companions). Persistence is achieved through LaunchAgents masquerading as legitimate updaters. The attack infrastructure uses Cloudflare-fronted delivery domains and dedicated RAT command-and-control servers. The vulnerability affects macOS versions prior to 5.8.0.24 and is rated critical with a CVSS 3.1 score of 9.8.
Potential Impact
Successful exploitation results in full compromise of affected macOS systems, including theft of browser credentials, keychain secrets, confirmed account passwords, Telegram sessions, SSH keys, and cloud credentials. The attack heavily targets cryptocurrency assets by phishing recovery phrases from numerous wallet browser extensions, desktop apps, and hardware wallet companions. The malware achieves persistence and stealth, enabling ongoing data exfiltration and remote access via a native Mach-O RAT and other components. This leads to high confidentiality, integrity, and availability impacts.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. In the absence of an official fix, users should avoid executing untrusted curl commands, especially those sourced from unverified websites or ads. Exercise caution when following installation instructions from unofficial sources. Monitor for suspicious LaunchAgents and network connections to known malicious infrastructure domains (agenticsora[.]com, malwareaudit[.]com) and IP addresses (103.216.221.95, 85.206.161.241:8443). Employ endpoint detection tools capable of identifying Mach-O RATs and TCC permission abuse. Follow vendor advisories for updates on patches or official mitigations.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- mitre
- Date Reserved
- 2024-12-13T00:00:00.000Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Indicators of Compromise
Cve
| Value | Description | Copy |
|---|---|---|
cveCVE-2024-55956 | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttp://com.apple.preference.security?Privacy_AllFiles | — | |
urlhttp://agenticsora.com/curl/ | — | |
urlhttp://agenticsora.com/dynamic?txd= | — | |
urlhttp://agenticsora.com/gate?buildtxd= | — | |
urlhttp://main.sdhomeinspectors.com/modules/wallets | — | |
urlhttp://main.southcarolinacounselor.com/modules/wallets | — | |
urlhttps://agenticsora.com/ledger/ | — | |
urlhttps://agenticsora.com/loader/agent/ | — | |
urlhttps://agenticsora.com/loader/capture-agent/ | — | |
urlhttps://main.sdhomeinspectors.com/modules/wallets' | — |
Domain
| Value | Description | Copy |
|---|---|---|
domainmalwareaudit.com | — | |
domainagenticsora.com | — | |
domainsdhomeinspectors.com | — | |
domainsldev.cz | — | |
domainsouthcarolinacounselor.com | — | |
domainmain.sdhomeinspectors.com | — | |
domainmain.southcarolinacounselor.com | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash9dd465d26c7d86b4a6f514a4b46b2295 | — | |
hash071bd109208eb1080ef525b5be394244cec467c59ffef5b8782cfb5e4850401d | — | |
hash230dff4bf9442a951dcd6898b2110924969a20668c20a43e3ceed6fcef65963e | — | |
hash31566a1df7070f30cb990aa5eab310c1d4e0266c8776e9438138e5438ec1cff8 | — | |
hash3ae26ed89d3a1a140edc89ca78513aba2895789ed0d0f64cad6605b6f2347c7e | — | |
hash3db8befc08dc02ab7a76b5193abd81653775e8f3ceac5864c7c2188b2dbd3c54 | — | |
hash78dea0693ac2d70bdf8be7588667a75910e43fd84397ad484e710e37369a30f7 | — | |
hash9c09c303fa058c2d3e179969bd58ca5523775ff2d310fb2f8266ac74cb21ee81 | — |
Threat ID: 68f7d9b6247d717aace26c4d
Added to database: 10/21/2025, 19:06:30 UTC
Last enriched: 07/31/2026, 12:41:05 UTC
Last updated: 07/31/2026, 19:22:52 UTC
Views: 131
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.