HomeTopics 1Advanced Persistent ThreatMacSync Malware Evolves Into a More Sophisticated Threat for Mac Users

MacSync Malware Evolves Into a More Sophisticated Threat for Mac Users

Date:

Related stories

spot_imgspot_imgspot_imgspot_img

A new version of the MacSync malware is showing how quickly macOS threats are evolving. First spotted in the wild in September 2026, the malware has moved beyond its earlier script-based roots and now uses native Swift and Objective-C components, more complex delivery techniques, and a persistent backdoor designed to keep access to compromised Macs. This is rapidly evolving macOS information stealer is taking a more sophisticated route into victims’ systems, combining malicious disk images, binary droppers, stolen credentials and a persistent backdoor.

Security researchers at Kaspersky say they identified a new MacSync infection chain in the wild in September 2026. The malware, previously seen primarily through AppleScript-based delivery and social-engineering campaigns, has now moved toward native Swift and Objective-C components and a considerably more complex delivery mechanism.

That evolution matters because MacSync is not simply trying to steal browser cookies or cryptocurrency credentials and leave. Its latest variant can establish persistence, collect sensitive developer and cloud credentials, download additional components and give attackers a continuing foothold on an infected Mac.

For developers, cryptocurrency users and employees who use Macs to access corporate environments, the threat reaches well beyond the compromised endpoint.

From Mac.c to MacSync: A Malware Family That Keeps Changing

MacSync is a relatively young malware family. Kaspersky says it was first advertised on the dark web in 2025 under the name Mac.c before being renamed MacSync by its operators.

Earlier versions were largely implemented using AppleScript and shared similarities with the AMOS infostealer family. The newer version represents a significant technical shift: the core malicious components are now native binaries written in Swift and Objective-C, while the infection chain incorporates multiple loaders and droppers.

Kaspersky classifies MacSync as a malware-as-a-service (MaaS) operation, meaning different criminal operators can potentially use the malware with their own delivery campaigns.

That helps explain why there is no single way for victims to become infected.

Researchers have observed MacSync distributed through social engineering and ClickFix-style attacks, as well as fake, cracked or nonexistent applications. In one campaign, attackers promoted a fake cryptocurrency wallet called Toria, complete with a dedicated website and promotion through X and Telegram.

For users, the lesson is familiar but increasingly important: on macOS, a convincing application installer can be just as dangerous as a malicious attachment or phishing page.

The New Infection Chain Uses DMG Files — and Even iCloud

The latest campaign begins with a malicious DMG disk image, a common format for distributing macOS applications.

Once the victim launches the application, the malware works through a chain of loaders, scripts and droppers before reaching the primary infostealer and backdoor.

One particularly unusual step involves Apple’s iCloud infrastructure.

According to Kaspersky, one sample retrieved its next-stage content through a publicly accessible iCloud calendar. The downloaded calendar contained malicious instructions in an event description, which were ultimately passed to the Zsh interpreter. The chain then retrieved an application archive from iCloud, removed macOS quarantine attributes, applied an ad-hoc signature and executed it.

This does not mean iCloud itself is compromised. Rather, the attackers are abusing legitimate infrastructure as part of their delivery chain.

That distinction is important for security teams. Blocking every legitimate cloud service is rarely practical. The challenge is identifying when trusted services are being used in an abnormal context.

Native Code Replaces Much of the Earlier Script-Based Approach

One of the biggest changes in MacSync is what happens after the initial compromise.

Earlier variants relied heavily on AppleScripts. The new campaign introduces executable modules written in Swift and Objective-C, making the malware more closely resemble conventional native macOS software.

The infection chain also uses several layers of encryption and decryption. Kaspersky observed AES-encrypted payloads, while a custom utility called pkgunpack uses Curve25519-based key exchange and AES-GCM to protect later-stage payloads. The malware also attempts to clear cryptographic material from memory after use, a technique that can make dynamic analysis and forensic recovery more difficult.

In other words, this is no longer a relatively simple script dropped onto a Mac.

It is a modular malware platform with multiple stages designed to make analysis harder and give operators more control over what eventually runs on the victim’s machine.

What MacSync Wants to Steal

The infostealer component is particularly concerning for developers and technical professionals because of the breadth of information it targets.

Kaspersky says the malware can collect:

  • Browser history and cookies
  • Saved browser logins and passwords
  • Cryptocurrency wallet extension data
  • Cryptocurrency application data
  • Telegram data
  • Device login credentials
  • Keychain-related data
  • SSH configuration
  • AWS configuration
  • Kubernetes configuration
  • Git configuration
  • Zsh and Bash command history
  • Installed applications
  • Running processes
  • Hardware and device information
  • System UUID information
  • Other application configuration files

The collected information is stored temporarily and packaged before being transmitted to the attackers’ infrastructure.

For an ordinary personal computer, that is already a serious privacy and financial risk.

For a developer’s workstation, it can become a supply-chain problem.

A compromised developer machine may contain cloud credentials, source-control tokens, SSH keys, CI/CD configuration, deployment credentials and access to production environments. Stealing those secrets can give attackers opportunities that extend far beyond the original Mac.

This is one reason why organizations should treat developer endpoints as privileged assets rather than simply another category of employee laptop.

MacSync Doesn’t Stop at Stealing Data

The latest MacSync sample also contains a backdoor designed to maintain access to the infected system.

Researchers found several persistence mechanisms, including a LaunchAgent, modifications to .zshrc, and changes involving Git hooks. The malware also maintains backup copies of components so that missing files can be restored.

The backdoor disguises itself as a Finder-related application and stores components under a directory inside the user’s Library that is not normally present on a standard macOS installation.

The backdoor communicates with command-and-control infrastructure and can receive commands from the attackers.

Among the capabilities documented by Kaspersky are commands that can:

  • Deploy browser extensions
  • Replace an installed Ledger wallet application
  • Collect additional system information or files
  • Upload files to the attackers
  • Execute AppleScript commands
  • Download and execute another component associated with browser traffic interception

The live_browser command is particularly noteworthy. Kaspersky says the command can download a component called sn_relay; its exact functionality was not established, but the researchers believe it may be intended to enable a man-in-the-middle capability against browser traffic.

That capability remains an area where organizations should pay close attention as the malware develops.

Developers and Crypto Users Are Especially Exposed

MacSync’s targeting provides an important clue about the threat actor’s priorities.

The malware is designed to collect cryptocurrency-related information, browser credentials, developer configurations, cloud credentials and authentication material. Its operators have also used fake applications that would appeal to crypto users and technical professionals.

Kaspersky therefore identifies developers, crypto enthusiasts and people working in IT and related fields as particularly relevant targets.

For businesses, the concern is not limited to the amount of data stolen from one workstation.

A developer’s Mac can act as a bridge into other systems.

An exposed Git credential could lead to source-code repositories. A stolen AWS configuration could expose cloud resources. SSH material could provide access to servers. Kubernetes credentials could potentially expose containerized workloads. Browser sessions can also provide attackers with access to business applications without necessarily requiring the victim’s password.

The compromise of one endpoint can therefore become the beginning of a much larger incident.

Why This Matters in the Middle East and Africa

The MacSync campaign is global rather than specifically regional, but its techniques are relevant to organizations across the Middle East and Africa.

Technology companies, financial institutions, cryptocurrency businesses, government organizations, consultancies and rapidly growing digital businesses increasingly rely on cloud platforms, developer environments and remote access.

That creates a particularly important security requirement: protect the credentials stored on developer and executive endpoints, not just the operating system itself.

Organizations in the region should also consider the human side of the attack. Fake applications promoted through social media, messaging platforms and professional networks can reach employees without passing through traditional corporate email security controls.

Security awareness therefore needs to cover software installation, cryptocurrency applications, developer tooling and social-media-based threats not only phishing emails.

Organizations reviewing their wider exposure can also consider structured cybersecurity services and security assessments from Saintynet Cybersecurity, particularly around endpoint security, vulnerability management, cloud security, IAM and security operations.

10 Actions Security Teams Should Take Now

1. Restrict application installation

Mac users should install software only from trusted sources and through approved organizational processes. Security teams should consider application allowlisting where appropriate.

2. Treat cracked and unofficial software as a high-risk category

“Free” versions of commercial applications are a recurring malware delivery mechanism. Organizations should explicitly prohibit pirated software and make legitimate alternatives easily available.

3. Monitor DMG and application execution

Endpoint security controls should monitor unusual DMG-mounted applications, newly executed binaries and applications attempting to modify quarantine attributes or establish persistence.

4. Protect developer credentials separately

SSH keys, Git credentials, cloud access keys, Kubernetes credentials and CI/CD secrets should not be treated like ordinary files. Use dedicated secret-management solutions, short-lived credentials and strong access controls wherever possible.

5. Monitor LaunchAgents and Login Items

Unexpected LaunchAgents, Login Items and other macOS persistence mechanisms deserve investigation—particularly when they appear in combination with recently installed applications.

6. Inspect shell and Git configuration

Security teams should review .zshrc, shell startup files and Git hooks for unauthorized commands or unexpected modifications. MacSync’s use of these locations makes them relevant forensic artefacts, according to Securelist.

7. Watch for unusual cloud-service behavior

A legitimate service such as iCloud being contacted by an application does not automatically indicate malicious activity. But unusual downloads, unexpected calendar activity or cloud services being used as intermediate payload-delivery infrastructure should be investigated.

8. Strengthen MFA and session protection

Enable phishing-resistant MFA for privileged accounts where possible. Revoke active sessions and rotate credentials following a suspected endpoint compromise.

9. Have a developer-device incident response procedure

A compromised developer Mac should trigger more than a standard endpoint cleanup. Security teams should determine which repositories, cloud environments, deployment systems, tokens and production resources the device could access.

10. Keep threat intelligence and security awareness current

Mac malware continues to evolve, and security teams should regularly update detection rules, EDR coverage, threat intelligence feeds and employee awareness material. Targeted cybersecurity training and awareness programs can help technical and non-technical users recognize fake software, social engineering and credential-theft campaigns.

Indicators of Compromise

Kaspersky has published hashes and infrastructure associated with the campaign, including indicators for the initial loader, malicious calendar, droppers, scripts, infostealer and backdoor.

The most useful hashes include:

Infostealer:
c53d0ea45dbc622afb7f16ea3eec78bc

Backdoor:
fc3ba5ed282d77127efd0b0f2403531b

Auxiliary persistence script:
7212229c85852c3bffaf9740002b2f39

Security teams should consult the original Kaspersky Securelist research for the complete IOC list, including additional hashes, URLs and C2 infrastructure, and validate those indicators against their own telemetry before taking action.

The Bigger Picture

MacSync is another reminder that the macOS threat landscape is not standing still.

The significance of this campaign is not simply that another information stealer has appeared. It is the combination of native malware, layered delivery, legitimate cloud infrastructure, credential theft, persistence and remote-control capabilities in a single infection chain.

The shift from predominantly AppleScript-based components toward Swift and Objective-C binaries also shows that malware developers are investing in deeper integration with the macOS environment.

For security leaders, the practical takeaway is straightforward: protecting a Mac today means protecting the identities, credentials, applications and development environments connected to it.

That is particularly true for developers and privileged users. Their laptops can hold the keys to source code, cloud infrastructure, cryptocurrency assets and production systems.

MacSync may begin with a fake application, but the potential consequences can reach much further.

Source: Kaspersky Securelist, “MacSync under the microscope: new delivery methods and a new payload,” published September 24, 2026.

Subscribe

- Never miss a story with notifications

- Gain full access to our premium content

- Browse free from up to 5 devices at once

Latest stories

spot_imgspot_imgspot_imgspot_img