The infection scheme | Image: Kaspersky Labs
At a Glance
| Attribute | Details |
|---|---|
| Malware Family | MacSync (originally advertised as Mac.c) |
| Threat Actor | Unknown cybercriminals (Malware-as-a-Service model; unconfirmed attribution) |
| Target Victims | Cryptocurrency investors, software developers, and macOS administrators |
| Delivery Vector | Malicious disk images (DMGs), fake crypto apps, and public iCloud calendars |
| Key Capabilities | Curve25519 key exchange, PAM credential validation, multi-layer persistence, data exfiltration |
| Source | Kaspersky Threat Intelligence (Securelist) |
Executive Summary
The operators behind the new MacSync macOS infostealer overhauled their architecture to compromise Apple computers. The campaign uses deceptive cryptocurrency websites and public iCloud calendar files to distribute multi-stage droppers. Once installed, the malware executes Swift and Objective-C modules that steal credentials, browser databases, and cryptocurrency assets.
Delivery and Deceptive Lures
Threat actors distribute MacSync through deceptive social engineering schemes and trojanized applications. Recently, the attackers created an entire promotional campaign for a fake cryptocurrency wallet application called Toria. They promoted this nonexistent application across social media channels like X and Telegram to lure victims.
When users click download buttons on these fake websites, they receive malicious disk image files. In earlier campaigns, the malware used basic AppleScript files and ClickFix lures. However, the newest variants use compiled application bundles and multi-stage binary droppers.
Additionally, some infection chains deliver payloads through public cloud infrastructure. The attackers created public iCloud calendar entries that hold malicious download commands inside event descriptions. The initial loader parses this calendar file and executes the embedded script commands directly in memory.
Multi-Stage Infection Chain
The infection chain advances through several stages to evade security defenses. First, the application bundle extracts an encrypted payload from its binary overlay. It strips the quarantine attribute from itself using native macOS command utilities.
Next, the loader retrieves an external script and executes it in the background. The script invokes a specialized decryption utility named pkgunpack. Instead of using static encryption keys, the utility performs an elliptic-curve key exchange with the remote server. As Kaspersky noted, “Without the server’s cooperation, the payload cannot be recovered statically.” Therefore, security analysts cannot decrypt the core payload without an active server connection.
Furthermore, intermediate droppers employ defensive checks before unpacking final payloads. The malware queries system parameters through sysctl to detect virtual machine environments. It also sets the PT_DENY_ATTACH flag with ptrace to prevent debuggers from attaching to the process.
Persistence and Alert Suppression
After completing the key exchange, the loader decrypts two distinct components: an infostealer and a backdoor. The installer copies the files into the Application Support directory and renames the bundle to Finder.app.
The malware installs several redundant persistence mechanisms. It registers a LaunchAgent that runs every 15 seconds. It also adds execution commands to the user shell configuration file and global Git hooks. To keep these changes quiet, the script pauses and terminates the background notification agent before creating the scheduled task.
Command-and-Control and Exfiltration Behavior
The main infostealer module is written in Swift and begins by presenting deceptive system prompts. The malware displays a fake authentication prompt asking for the user’s administrative password. Once entered, the application validates the password using the Pluggable Authentication Modules interface. Kaspersky researchers noted that this technique was “first observed in the wild in July 2026 in the PamStealer family.”
Next, the infostealer harvests extensive data from the compromised system. It collects saved passwords and cookies from major browsers like Chrome, Edge, Safari, Brave, and Firefox. It also extracts credentials from desktop cryptocurrency wallets and Telegram sessions. Furthermore, the malware collects SSH keys, cloud configuration files, and the user profile photo using directory service tools.
The malware packages the stolen data and uploads it to the command server in 90-megabyte chunks using HTTP PUT requests. Each request carries a static authorization token in a custom header. Meanwhile, the secondary backdoor module is written in Objective-C. It connects to the command server to receive tasking instructions. The backdoor can deploy rogue browser extensions, replace legitimate Ledger wallet applications, or execute remote AppleScript commands.
Threat Actor Attribution
Kaspersky researchers attribute this activity to cybercriminals operating under a Malware-as-a-Service model. The developers lease the tool to independent affiliates, so specific operator identities remain unconfirmed. However, the operational targets and crypto themes indicate financially motivated actors.
Defense and Detection Guidance
Organizations must apply proactive endpoint controls to defend against the MacSync macOS infostealer. System administrators should inspect the Application Support folder for unauthorized directories mimicking system software. In addition, security teams must monitor changes to shell startup files and global Git hooks.
Users should avoid downloading cryptocurrency applications from unverified sources. Defenders can read the complete technical analysis in the Kaspersky report on the MacSync infostealer. Implementing application allowlists and monitoring background task management services helps protect enterprise Mac fleets.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!