KASPERSKY researchers have reported a redesigned MacSync macOS infostealer, previously advertised as Mac.c, being distributed through fake cryptocurrency applications and deceptive websites. One campaign promoted a non-existent wallet called Toria on X and Telegram before directing users to malicious disk image (DMG) files. Other infection chains use public iCloud calendar entries containing download commands. The malware is offered under a Malware-as-a-Service model, but the operators’ identities remain unconfirmed.
The multi-stage loader extracts an encrypted payload, removes macOS quarantine attributes and retrieves scripts in the background. Its `pkgunpack` utility uses an elliptic-curve key exchange with the command server, meaning the core payload cannot be recovered statically without server cooperation, according to Kaspersky. The malware checks for virtual machines, blocks debugger attachment and installs persistence through a LaunchAgent, shell configuration files and global Git hooks. It deploys a Swift infostealer and an Objective-C backdoor, renaming the bundle to `Finder.app` and running the LaunchAgent every 15 seconds.
MacSync displays a fake administrator authentication prompt and validates the supplied password through PAM. It can steal browser passwords and cookies from Chrome, Edge, Safari, Brave and Firefox, along with cryptocurrency-wallet credentials, Telegram sessions, SSH keys, cloud configuration files and other user data. Stolen information is sent to the command server in 90-megabyte chunks using HTTP PUT requests.
The backdoor can install malicious browser extensions, replace Ledger applications and execute AppleScript commands. Kaspersky recommends checking Application Support, shell startup files and global Git hooks for unauthorised changes, while users should avoid cryptocurrency software from unverified sources.