216.73.217.22

Inside MacSync's Script-Driven Stealer and Hardware Wallet App Trojanization

· Published 21/01/2026 18:46 · Modified 22/01/2026 14:49

Export JSON

Essential information

Published
21/01/2026 18:46
Modified
22/01/2026 14:49
Tags
2026-01-21 cryptocurrency electron hardware-wallet infostealer macos macsync phishing trojanization
Related entities
6 observables, 16 techniques (mitre), 23 others

Description

is a sophisticated that targets users. It is delivered through a lure disguised as a cloud storage installer, tricking users into executing a malicious Terminal command. The malware employs a multi-stage infection process, using a script-based approach to harvest browser credentials, wallet data, and sensitive files. A key feature of is its ability to trojanize popular -based applications like Ledger and Trezor, enabling long-term and data exfiltration. The malware's infrastructure includes multiple rotating C2 domains and clone sites, indicating an ongoing and evolving campaign. 's focus on -related data and its stealthy, script-based execution make it particularly dangerous for users in the crypto community.

External references