Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
OnePlus OxygenOS Critical Flaws Let Zero-Permission Apps Gain Root Access
September 25, 2026
Critical Linux Kernel Flaw (CVE-2024-0001) Lets Local Users Gain Root, Escape Containers
September 25, 2026
AI-Powered Botnet “DarkGate” Found Operating Inside Compromised Servers
September 25, 2026
Home/Threats/MacSync Malware Transforms macOS Apps for Crypto and Password Theft
Threats

MacSync Malware Transforms macOS Apps for Crypto and Password Theft

Key Takeaways MacSync, a macOS information stealer, has adopted a sophisticated new infection chain. The malware targets cryptocurrency users and developers, stealing credentials, wallet data, and...

Emy Elsamnoudy
Emy Elsamnoudy
September 25, 2026 5 Min Read
9 0

Key Takeaways

  • MacSync, a macOS information stealer, has adopted a sophisticated new infection chain.
  • The malware targets cryptocurrency users and developers, stealing credentials, wallet data, and development-related keys.
  • New delivery methods include malicious disk images disguised as legitimate apps and a novel use of public iCloud calendars for command and control.
  • MacSync employs advanced evasion techniques, including compiled code (Swift, Objective-C), virtual machine checks, and debugger blocking.
  • Persistence mechanisms are robust, making complete removal challenging without thorough investigation.

MacSync Evolves with Advanced macOS Attack Chain

A highly adaptable macOS information stealer, known as MacSync, has re-emerged with a significantly more complex attack chain. This updated variant specifically targets individuals involved in cryptocurrency and software development, aiming to compromise sensitive data and credentials.

Table Of Content

  • Key Takeaways
  • MacSync Evolves with Advanced macOS Attack Chain
  • Sophisticated Delivery and Persistence
  • Data at High Risk: Passwords, Wallets, and Developer Tools
  • What You Should Do
  • Indicators of Compromise (IoCs)

The latest iteration of MacSync no longer primarily relies on simple Terminal commands for initial compromise. Instead, threat actors are now leveraging malicious disk-image files that masquerade as legitimate applications. This shift allows operators to diversify their delivery methods across different campaigns, enhancing their stealth and reach.

Victims are typically lured into installing the malware through deceptive means, such as fake or cracked software. A notable example is a non-existent cryptocurrency wallet application named “Toria,” which attackers actively promoted on social media platforms.

Upon execution, the malicious application can bypass macOS quarantine attributes, download additional malicious components, and ultimately deploy tools designed to exfiltrate passwords, cryptocurrency wallet data, and vital work-related credentials.

Sophisticated Delivery and Persistence

Security researchers at Securelist detected this new infection chain in September 2026. Their analysis highlighted a clear strategic pivot from script-heavy delivery to the use of compiled components written in Swift and Objective-C. Kaspersky said in a report shared with Cyber Security News (CSN) that this change provides MacSync with greater operational flexibility and more effective obfuscation techniques, enabling it to operate stealthily on both Apple Silicon and Intel-based Macs. It is important to note that not all MacSync campaigns utilize this specific, advanced chain.

The infection process typically begins with a malicious DMG file containing an application bundle. One observed attack route executes a compiled JavaScript for Automation (JXA) script directly in memory. Another, more elaborate pathway involves a loader that deploys multiple droppers before fetching the final malicious components. This represents a significant evolution from previous MacSync delivery methods, such as the “ClickFix” technique. Both infection paths ultimately lead to the deployment of information-stealing and remote-control capabilities.

A particularly insidious aspect of the new loader is its ability to retrieve an encrypted address, which, in at least one instance, was found to be a public iCloud calendar. The calendar event’s description cleverly conceals commands that download an archive containing another application. These commands then strip the application’s security markings, apply an ad-hoc signature, and execute it. This innovative use of a common cloud-sharing feature turns an innocuous service into an unexpected vector for malware delivery.

In its later stages, MacSync decrypts and deploys an information stealer and a backdoor. The malware employs temporary and lock files to manage its execution flow, while completed modules meticulously erase logs and other forensic traces. Furthermore, MacSync incorporates anti-analysis techniques, such as checking for virtual machine environments and blocking debuggers, making detection and investigation considerably more difficult on infected devices.

MacSync is designed for robust persistence, often masquerading as the legitimate macOS Finder application. It maintains its presence through various mechanisms, including a LaunchAgent, modifications to ZSH startup settings, and the manipulation of global Git hooks. A “repair routine” is also implemented to restore compromised files and suppress startup notifications, ensuring the malware’s continued operation even if initial malicious applications are removed. This sophisticated persistence means that merely deleting the initial infected application may not be sufficient to eradicate the intrusion.

Data at High Risk: Passwords, Wallets, and Developer Tools

The Swift-based information stealer component of MacSync employs a convincing social engineering tactic: it displays a fake administrator password prompt tailored to the application it is mimicking. After a victim enters their password, the malware presents a fabricated “damaged app” alert, making the installation failure seem like a routine system issue. Crucially, the malware verifies the entered password using legitimate macOS authentication interfaces, a more advanced approach than older command-line methods.

Once established, MacSync aggressively harvests a wide array of sensitive data. This includes browser history, cookies, saved login credentials, cryptocurrency wallet extension data, macOS Keychain files, Telegram information, and detailed device specifics. Beyond personal data, the malware specifically targets configuration files and histories associated with development tools such as SSH, ZSH, AWS, Kubernetes, and Git. This extended reach into software development workflows is particularly concerning, as these files often contain access tokens or credentials for cloud services and code repositories, potentially enabling attackers to breach corporate environments, as previous MacSync campaigns involving fake installers have demonstrated. The full extent of infections remains unknown, as researchers did not disclose victim counts.

The embedded backdoor component communicates with command-and-control (C2) servers over HTTP. It is capable of receiving various commands, uploading exfiltrated files, deploying malicious browser extensions, and even replacing an installed Ledger hardware wallet application with a compromised version. While researchers were unable to fully determine the precise function of a “live-browser” feature, it suggests potential capabilities for intercepting browser traffic. The specific command scripts used by the attackers were not available for analysis.

What You Should Do

  • Source Software Carefully: Always download applications exclusively from official developer websites or trusted app stores. Avoid using cracked software, pirated versions, or applications from unverified third-party sources.
  • Exercise Caution with Prompts: Never bypass macOS security warnings, paste unverified commands into the Terminal, or approve unexpected password prompts, especially if they appear immediately after launching a new application.
  • Monitor for Suspicious Activity: Regularly review startup items, check for altered Git hooks, and monitor network traffic for suspicious outbound connections or large uploads.
  • Incident Response: If a MacSync infection is suspected, immediately isolate the affected machine from the network. Revoke all active sessions and change all compromised credentials (passwords, API keys, SSH keys) from a known clean device.
  • Thorough Remediation: Before bringing an infected Mac back online, ensure a comprehensive review of all potential persistence points (LaunchAgents, ZSH settings, Git hooks, hidden directories) has been completed to confirm the malware’s complete removal.

Indicators of Compromise (IoCs)

Type Indicator Description
MD5 26a0f7cdb9f7dc5ace9a40af825b1538 Stage one loader.
MD5 2d69812584269699fade26622e6490c5 Stage one loader.
MD5 7df1049cbd56c0bfa4a3364a379b4c2c Stage one loader.
MD5 9f15fe9c4415cd668334339f705b94d8 Stage one loader.
MD5 fb90887592655a8c989e443c640167aa Stage one loader.
MD5 6791dad263cac6d63ebba6a4b57e7d71 Stage one loader.
MD5 3ded1d71a822b53b12c3b67bcaf633f5 Malicious calendar, stage two.
MD5 781ce50001d4b449600afa347c9b0208 Stage three dropper.
MD5 8e84b01d5ac9624f0b181ade0e737193 Stage three dropper.
MD5 980e2134679bc0c609f7659882883d77 Stage three dropper.
MD5 4203ec932bfcc0907f91732440d6d997 Stage three dropper.
MD5 eb760d5c88f13f7ee0f8f86ba3407123 Stage three dropper.
MD5 f9f70096aabb4d22a6657014f4853a53 Stage three dropper.
MD5 3deeed48fd38f22e369f5c3092bd68a1 Stage four dropper.
MD5 f97d24212fa6a21be0c4d211e10f044c Stage five script.
MD5 00d12d842596bf5ee1805effb4571d30 Stage six script.
MD5 9a0043d900a9ac78c886c59c9a328fd0 Stage six script.
MD5 7212229c85852c3bffaf9740002b2f39 Auxiliary repair script.
MD5 c53d0ea45dbc622afb7f16ea3eec78bc Infostealer.
MD5 fc3ba5ed282d77127efd0b0f2403531b Backdoor.
MD5 8dc8561349d144d4661bc66f2ec49f9f Auxiliary autorun tool.
URL hxxps://toria[.]app/ Fake wallet website.
URL hxxps://warpcast[.]asia/Toria.dmg Malicious disk-image location.
URL hxxps://streamyard.appstore.com[.]mx/installer.sh Installer script location.
URL hxxps://slack.apple03cloudstore[.]com/installer.sh Installer script location.
URL hxxps://toria.apple03cloudstore[.]com/ Reported malicious URL.
URL hxxps://waaako.appstore.com[.]mx/installer.sh Installer script location.
URL hxxps://toria.apple03cloudstore[.]com/e3c1a6b00bc31e14/stage2.enc Encrypted stage-two payload.
URL hxxps://docsend.appstore.com[.]mx/dcc737d157ef4271/stage2.enc Encrypted stage-two payload.
URL hxxps://docsend.appstore.com[.]mx/dcc737d157ef4271/CoreUpdate.pkg.enc Encrypted package.
URL hxxps://docsend.appstore.com[.]mx/dcc737d157ef4271/Helper.pkg.enc Encrypted helper package.
URL hxxp://caldav.icloud[.]com/published/2/MTk1NDMwMDMzNTUxOTU0M1aHCZ-nMxiyGzBTzPiodOf44DtKJ6PpjftAG28_ui2NCYMpL_vu4pF4ddsJ8ysg0QI7pR0VEIEbZYdilVZRw08 Calendar URL shown in the infection-chain analysis.
URL hxxps://caldav.icloud[.]com/published/2/MTk1NDMwMDMzNTUxOTU0M1aHCZ-nMxiyGzBTzPiodOf44DtKJ6PpjftAG28_ui2NCYMpL_vu4pF4ddsJ8ysg0QI7pR0VEIEbZYdilVZRw08 Calendar URL listed in the report’s IoCs.
URL hxxps://gateway.icloud[.]com/caldav/1_MTk1NDMwMDMzNTUxOTU0M0pybtJB186GzhogprwCQUjY3oZNiDFHH8WVo6bmgUtI/attach/4GE4TKNBTGAYDGMZVGUYTSNJUGOAALDAFMDOJBGWNUCYJLZRNDCLCO2YMQ3I64RLGMNXVG3KYBPWQOGYIEI7MPBDDYHECFDYVENTXIYFNDCPOVRMCTYI236RCYZAE63V5U3RTUYGUMO2CO7PKCLWMCXE73M7OPTHSGRWH5DXQ4PCUQU4ELZTLW54JSTK2H7VQ6PD26WOA2R7PPIQ6RTJWDEWP34U3HB4YWMXXC6EJ6PKWILSPYRSDEVY6QGMWSIUN6PR5W35KO3D4QZE7CFPUVBAEKI/Loader.app.tar.gz/YXR0YWNoYXR0YWNoYXR0YRhrE8mQ0E-b_dTUSGStQgTQ0ULFxCanei3Ke-EuEyQL iCloud archive attachment.
C2 URL hxxps://docsend.appstore[.]com[.]mx Command-and-control address.
C2 URL hxxps://toria.apple03cloudstore[.]com Command-and-control address.
HTTP access token b8b4b88205a8f594b95a841bc37342898f34cad8a5a9e4a22ce69a31a1208650 Observed value for the X-Upload-Token header.
HTTP access token ff3ab9ef841630364818396f62e696b72aed162cf0b895b6643ef25dad79b51d Observed value for the X-Upload-Token header.
File artifact /tmp/.sys-<16-digit random value> Temporary dropper path pattern.
File artifact /tmp/*.lock Lock-file pattern used to prevent repeat execution.
File artifact .ZSHRC Shell startup file modified for persistence.
File artifact .repair-run Script used to restore backdoor persistence.
Directory $HOME/Library/Application Support/System Backdoor files and backup location.
LaunchAgent com.apple.finder.agent Backdoor persistence name.
Git hook pre-commit Global hook modified for persistence.
Git hook post-checkout Global hook modified for persistence.
Log file $HOME/Library/Logs/.sysnotif-agent.log Backdoor log location.
Archive /tmp/osalogging.zip Archive used by the backdoor’s data-collection command.
File name KcHelper Helper sought by a feature disabled in observed samples.
File name sn_relay Additional backdoor resource whose purpose was not confirmed.
Utility pkgunpack Payload key-generation and decryption utility.
URL path /loader/ Path prefix for a backdoor executable on the C2 server.
URL path /v1/agent/ping Backdoor command-check endpoint.
URL path /v1/agent/refresh Backdoor access-token refresh endpoint.
URL path /v1/asset/<upload_id>/init File-upload initialization endpoint.
URL path /v1/asset/<upload_id> File-upload endpoint.
URL path /v1/agent/<command_status> Command-status telemetry endpoint.

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwareSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Cloudflare Container Vulnerability CVE-2024-4683 Exposes Customer Data

Next Post

Duelbits Confirms $7 Million Hot Wallet Hack, Systems Offline

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Sauron Loader Malware Evades Detection with DLL Side-Loading
September 25, 2026
Critical WordPress Comment2Shell RCE Vulnerability CVE-2022-0215 Patched
September 25, 2026
Critical ServiceNow Vulnerabilities Let Attackers Bypass Authorization
September 25, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us