MacSync Malware Transforms macOS Apps for Crypto and Password Theft
Key Takeaways MacSync, a macOS information stealer, has adopted a sophisticated new infection chain. The malware targets cryptocurrency users and developers, stealing credentials, wallet data, and...
Key Takeaways
- MacSync, a macOS information stealer, has adopted a sophisticated new infection chain.
- The malware targets cryptocurrency users and developers, stealing credentials, wallet data, and development-related keys.
- New delivery methods include malicious disk images disguised as legitimate apps and a novel use of public iCloud calendars for command and control.
- MacSync employs advanced evasion techniques, including compiled code (Swift, Objective-C), virtual machine checks, and debugger blocking.
- Persistence mechanisms are robust, making complete removal challenging without thorough investigation.
MacSync Evolves with Advanced macOS Attack Chain
A highly adaptable macOS information stealer, known as MacSync, has re-emerged with a significantly more complex attack chain. This updated variant specifically targets individuals involved in cryptocurrency and software development, aiming to compromise sensitive data and credentials.
Table Of Content
The latest iteration of MacSync no longer primarily relies on simple Terminal commands for initial compromise. Instead, threat actors are now leveraging malicious disk-image files that masquerade as legitimate applications. This shift allows operators to diversify their delivery methods across different campaigns, enhancing their stealth and reach.
Victims are typically lured into installing the malware through deceptive means, such as fake or cracked software. A notable example is a non-existent cryptocurrency wallet application named “Toria,” which attackers actively promoted on social media platforms.
Upon execution, the malicious application can bypass macOS quarantine attributes, download additional malicious components, and ultimately deploy tools designed to exfiltrate passwords, cryptocurrency wallet data, and vital work-related credentials.
Sophisticated Delivery and Persistence
Security researchers at Securelist detected this new infection chain in September 2026. Their analysis highlighted a clear strategic pivot from script-heavy delivery to the use of compiled components written in Swift and Objective-C. Kaspersky said in a report shared with Cyber Security News (CSN) that this change provides MacSync with greater operational flexibility and more effective obfuscation techniques, enabling it to operate stealthily on both Apple Silicon and Intel-based Macs. It is important to note that not all MacSync campaigns utilize this specific, advanced chain.
The infection process typically begins with a malicious DMG file containing an application bundle. One observed attack route executes a compiled JavaScript for Automation (JXA) script directly in memory. Another, more elaborate pathway involves a loader that deploys multiple droppers before fetching the final malicious components. This represents a significant evolution from previous MacSync delivery methods, such as the “ClickFix” technique. Both infection paths ultimately lead to the deployment of information-stealing and remote-control capabilities.
A particularly insidious aspect of the new loader is its ability to retrieve an encrypted address, which, in at least one instance, was found to be a public iCloud calendar. The calendar event’s description cleverly conceals commands that download an archive containing another application. These commands then strip the application’s security markings, apply an ad-hoc signature, and execute it. This innovative use of a common cloud-sharing feature turns an innocuous service into an unexpected vector for malware delivery.
In its later stages, MacSync decrypts and deploys an information stealer and a backdoor. The malware employs temporary and lock files to manage its execution flow, while completed modules meticulously erase logs and other forensic traces. Furthermore, MacSync incorporates anti-analysis techniques, such as checking for virtual machine environments and blocking debuggers, making detection and investigation considerably more difficult on infected devices.
MacSync is designed for robust persistence, often masquerading as the legitimate macOS Finder application. It maintains its presence through various mechanisms, including a LaunchAgent, modifications to ZSH startup settings, and the manipulation of global Git hooks. A “repair routine” is also implemented to restore compromised files and suppress startup notifications, ensuring the malware’s continued operation even if initial malicious applications are removed. This sophisticated persistence means that merely deleting the initial infected application may not be sufficient to eradicate the intrusion.
Data at High Risk: Passwords, Wallets, and Developer Tools
The Swift-based information stealer component of MacSync employs a convincing social engineering tactic: it displays a fake administrator password prompt tailored to the application it is mimicking. After a victim enters their password, the malware presents a fabricated “damaged app” alert, making the installation failure seem like a routine system issue. Crucially, the malware verifies the entered password using legitimate macOS authentication interfaces, a more advanced approach than older command-line methods.
Once established, MacSync aggressively harvests a wide array of sensitive data. This includes browser history, cookies, saved login credentials, cryptocurrency wallet extension data, macOS Keychain files, Telegram information, and detailed device specifics. Beyond personal data, the malware specifically targets configuration files and histories associated with development tools such as SSH, ZSH, AWS, Kubernetes, and Git. This extended reach into software development workflows is particularly concerning, as these files often contain access tokens or credentials for cloud services and code repositories, potentially enabling attackers to breach corporate environments, as previous MacSync campaigns involving fake installers have demonstrated. The full extent of infections remains unknown, as researchers did not disclose victim counts.
The embedded backdoor component communicates with command-and-control (C2) servers over HTTP. It is capable of receiving various commands, uploading exfiltrated files, deploying malicious browser extensions, and even replacing an installed Ledger hardware wallet application with a compromised version. While researchers were unable to fully determine the precise function of a “live-browser” feature, it suggests potential capabilities for intercepting browser traffic. The specific command scripts used by the attackers were not available for analysis.
What You Should Do
- Source Software Carefully: Always download applications exclusively from official developer websites or trusted app stores. Avoid using cracked software, pirated versions, or applications from unverified third-party sources.
- Exercise Caution with Prompts: Never bypass macOS security warnings, paste unverified commands into the Terminal, or approve unexpected password prompts, especially if they appear immediately after launching a new application.
- Monitor for Suspicious Activity: Regularly review startup items, check for altered Git hooks, and monitor network traffic for suspicious outbound connections or large uploads.
- Incident Response: If a MacSync infection is suspected, immediately isolate the affected machine from the network. Revoke all active sessions and change all compromised credentials (passwords, API keys, SSH keys) from a known clean device.
- Thorough Remediation: Before bringing an infected Mac back online, ensure a comprehensive review of all potential persistence points (LaunchAgents, ZSH settings, Git hooks, hidden directories) has been completed to confirm the malware’s complete removal.
Indicators of Compromise (IoCs)
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.