A substantially reworked version of MacSync, a fast-evolving macOS infostealer first advertised on the dark web as Mac.c in 2025, is distributed under a malware-as-a-service (MaaS) model. The latest variant appeared in the wild in September 2026 with a more complex, binary-driven infection chain, Kaspersky's Securelist team reports. MacSync Infection Chain Weaponizes iCloud CalDAV The […]

Key Takeaways
Payload overhaul: MacSync moved from AppleScript droppers to binary payloads written in Objective-C and Swift.
iCloud abuse: Attackers use a public iCloud CalDAV calendar to stage the next infection stage.
Prime targets: The stealer chases developers and crypto users through fake apps like the Toria wallet.
A substantially reworked version of MacSync, a fast-evolving macOS infostealer first advertised on the dark web as Mac.c in 2025, is distributed under a malware-as-a-service (MaaS) model. The latest variant appeared in the wild in September 2026 with a more complex, binary-driven infection chain, Kaspersky's Securelist team reports.
MacSync Infection Chain Weaponizes iCloud CalDAVThe campaign starts with malicious DMG images carrying an .APP loader that strips the com.apple.quarantine attribute and decrypts a staged URL, the analysis said.
In at least one sample, that link pointed to a public iCloud CalDAV calendar, whose event description hid shell commands piped into zsh -s.
Infection scheme | Source: KasperskyA chain of binary droppers, complete with anti-debugging checks, pulls encrypted infostealer and backdoor modules.
Swift Infostealer and Objective-C BackdoorThe Swift infostealer harvests browser data, cryptocurrency wallet files, Telegram data, the Keychain, and SSH, AWS, and Kubernetes configs.
It verifies the admin password through the PAM API, a technique first observed in the Pam Stealer family in July 2026, rather than the usual dscl.
MacSync, masquerading as a nonexistent crypto wallet app called Toria, promoted on X and Telegram | Source: KasperskyThe Objective-C backdoor disguises itself as Finder, persists via a LaunchAgent named com.apple.finder.agent, and supports deploy_ext, deploy_ledger, regrab, and live_browser commands, the last hinting at browser MitM capability.
Developers and Crypto Users in the CrosshairsThe data suggests developers, crypto enthusiasts, and other users connected in some way to IT and the crypto space are the main targets, with lures including a fake Toria wallet app promoted on X and Telegram.
Compromised developer machines expand attacker reach into corporate systems, raising the stakes for defenders tracking this threat.
In other news, reports last week indicated that fake Bitrefill checkouts spread through search results. An August Huntress report said a MacOS ClickFix scam steals crypto gradually.
Explore More
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | Your uncle’s frozen Mac says it’s infected after viewing a Google ad. Now what? | 0 | 10 | 25-09-2026 |
| 2 | macOS: Metas Muse-Agent war per ClickFix übernehmbar | 0 | 14.22 | 25-09-2026 |
| 3 | Cloudflare Fixes Cross-Tenant Data Exposure Bug in Containers | 0 | 11.48 | 25-09-2026 |
| 4 | Elsevier LAPSUS$ Redirect Attack: Visitors Sent to Leak Page Instead of Journals | 0 | 10.81 | 24-09-2026 |
| 5 | Navigating Cyber Disclosures in 2026: A Limited Renewal of CISA 2015, and “Take Two” on Finalizing CIRCIA’s Reporting Regulations | 0 | 11.74 | 26-02-2026 |
| 6 | heise-Angebot: iX-Workshop: Cybersecurity im KMU – vom Sicherheitscheck zum Maßnahmenplan | 0 | 13.38 | 26-09-2026 |
| 7 | WordPress CVE-2026-87902 Under Active Attack: Critical RCE Flaw Exploited Within Hours | 0 | 13.59 | 24-09-2026 |
| 8 | Выпуск M-Commander 6.1.0, форка файлового менеджера Midnight Commander | 0 | 17.41 | 27-09-2026 |
| 9 | Autodesk CER Service 7.3.0 Windows | 0 | 10.3 | 11-09-2026 |
| 10 | Microsoft released Windows 11 KB5127216, KB5125758 setup and recovery updates | 0 | 21.31 | 26-09-2026 |