A new macOS stealer malware, dubbed Mac.c, has appeared on a dark web forum and claims to offer ultra-fast data extraction for just $1,500 per month.

It was developed by cybercriminal “mentalpositive” and is advertised as a simplified alternative to the already known tool AMOS stealer, targeting credentials, crypto wallets, and system metadata.
Early samples show that the malware leverages native macOS tools and APIs to hide its activities, making it a significant threat to both businesses and consumers. Early reports indicate that Mac.c is already active and the threat is spreading rapidly.
In his promotional posts, mentalpositive emphasizes the small size of the binary, detection avoidance techniques, and the user-friendly control panel.
See also: Malicious Go module steals credentials via Telegram Bot
The control panel allows operators to create unique builds, monitor infections, and manage campaigns through a web environment.
Moonlock analysts noted that Mac.c 's modular design is largely similar to that of AMOS , but it lacks some advanced features, such as extensive crypto wallet targeting and a built-in keylogger.
However, the result is a faster, lighter tool , aimed at less experienced criminals entering the macOS malware market

Beyond its competitive pricing, Mac.c stands out for its use of incremental communication through standard system utilities.
Using AppleScript and built-in command-line tools, the malware minimizes external dependencies and limits the digital footprint for forensic analysis.
See also: Tableau Server: Critical vulnerability allows system compromise
Moonlock researchers identified that Mac.c begins data extraction by creating an AppleScript process to pull entries from Keychain, then compresses and uploads the stolen data over encrypted HTTPS to servers controlled by the attackers. This approach not only improves secrecy, but also bypasses many traditional endpoint defenses.
Initial estimates indicate that Mac.c has already been detected in real macOS environments. CleanMyMac telemetry data recorded several variants with names such as:
Installer.dmg,
Installer(1).dmg, and
Installer descrakeador adobe.dmg,
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
with the latter appearing as a cracked Adobe installer.
Although security tools prevented complete breaches, the number of incidents indicates that the malware is in an active distribution phase and is increasingly being adopted by malicious actors.
Infection Mechanism and Persistence
Mac.c infection begins with a phishing email or through malicious advertisements (malvertising) , which urge the user to download a supposedly innocent macOS installer.
See also: New Android malware mimics Russian FSB antivirus
Upon execution, the malware places a Launch Agent in:
~/Library/LaunchAgents/com.apple.update.plist,
thus ensuring persistence across reboots.
The following snippet shows how Mac.c writes the relevant persistence plist:
<?xml version=”1.0″ encoding=”UTF-8″?>
<!DOCTYPE plist PUBLIC “-//Apple//DTD PLIST 1.0//EN”
“https://www.apple.com/DTDs/PropertyList-1.0.dtd”>
<plist version=”1.0″>
<dict>
<key>Label</key>
<string>com.apple.update</string>
<key>ProgramArguments</key>
<array>
<string>/usr/bin/osascript</string>
<string>/tmp/.macc.scpt</string>
</array>
<key>RunAtLoad</key>
<true/>
</dict>
</plist>
Once installed, the loader uses AppleScript to extract items from Keychain and credentials stored in browsers, looping through a predefined list of supported browsers: Chrome, Edge, Brave , and Yandex.

By exploiting legitimate scripting interfaces, Mac.c maintains a low profile while simultaneously achieving data theft with serious consequences, making it a potent threat in the ever-evolving macOS malware landscape.
See also: Apple vulnerability: PoC Exploit released for zero-day bug
macOS malware protection
Apple offers some built-in security features, such as Gatekeeper and XProtect to prevent infection.
But there are some other methods of protection:
- Keep your operating system and software up to date to patch any known vulnerabilities
- Be cautious when downloading and opening attachments or files from unknown sources
- Use a reliable antivirus software, especially if you frequently download files from the Internet.
- Enable FileVault, which encrypts your data and protects it in case of theft or unauthorized access.
- Regularly back up your important files to an external hard drive
