MacSync Stealer Joins Lazarus 'Mach-O Man' in macOS Crypto Wallet Attacks
Blockchain security firm SlowMist disclosed MacSync Stealer v1.1.2 on April 22, 2026, targeting macOS users' crypto wallets via fake AppleScript dialogs and Keychain theft, hours after Bitso’s Quetzal Team and ANY.RUN revealed Lazarus Group's four-stage 'Mach-O Man' Go malware. Mach-O Man uses Telegram Bot API exfiltration, social-engineered Terminal lures, and LaunchAgent persistence, while MacSync also steals SSH, AWS, and Kubernetes keys, masking as errors. These back-to-back threats heighten self-custody risks, erode retail confidence, spur Bitcoin volatility, and drive calls to audit LaunchAgents and block suspicious traffic.