KASPERSKY researchers say a new version of the MacSync malware family was observed in the wild in September 2026. MacSync, previously advertised as Mac.c, is a malware-as-a-service infostealer aimed mainly at developers, cryptocurrency users and others working in IT. It has been distributed as fake or cracked applications, including a purported crypto wallet called Toria, and now begins with malicious DMG files.
Kaspersky found that attackers have replaced earlier AppleScript-based droppers with binary loaders and payloads written in Swift and Objective-C. In one observed chain, an application removed macOS quarantine attributes, retrieved an encrypted URL and used a public iCloud calendar to obtain shell commands and a further application archive. Later stages used multiple encrypted droppers, anti-virtual-machine and anti-debugging checks, and in-memory execution.
The infostealer requests an administrator password using a fake warning about a corrupted application, then collects browser history, cookies, saved credentials, cryptocurrency-wallet data, Telegram data, Keychain files, system information, SSH and cloud configuration files, shell histories and other material. The data is compressed and sent to the operators.
A separate backdoor establishes persistence through a LaunchAgent, ZSH configuration and Git hooks, disguising itself as Finder and suppressing some macOS notification processes. It communicates with command-and-control servers over HTTP and can execute AppleScript commands, deploy browser extensions, replace a Ledger wallet, collect files again and potentially interfere with browser traffic.
Kaspersky said the evidence points to an expanded risk when developers’ devices are compromised, as stolen credentials and software-development data could enable further attacks. The report provides hashes, domains and other indicators of compromise for detection.