MacSync’s New Infection Chain Shows How Mac Malware Is Becoming More Sophisticated
Kaspersky reports MacSync’s new macOS chain uses native loaders, iCloud staging, an infostealer, and a persistent backdoor.
Kaspersky observed a September 2026 MacSync campaign that replaces earlier AppleScript delivery with Swift and Objective-C Mach-O loaders for Apple Silicon and Intel Macs. Victims run a malicious DMG posing as the Toria cryptocurrency wallet; later stages abuse an iCloud calendar, then decrypt payloads with Curve25519 and AES-GCM. The final stage is a credential and wallet stealer plus a Finder-disguised backdoor that persists through a LaunchAgent, shell profiles, and Git hooks.
- Distributed as a fake Toria crypto-wallet DMG via a site, X, and Telegram
- Abuses an iCloud CalDAV calendar as a post-compromise staging channel
- Steals browser, Keychain, wallet, SSH, AWS, Kubernetes, and Git data
- Backdoor persists through a LaunchAgent, .zshrc changes, and Git hooks
- Kaspersky detects the family as HEUR:Trojan.OSX.MacSync variants
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | apple03cloudstore.com | streamyard.appstore.com[.]mx/installer.sh URL hxxps://slack.apple03cloudstore[.]com/installer.sh URL hxxps://toria.apple03cloudstore[.]com/ C |
| domain | com.mx | //warpcast[.]asia/Toria.dmg URL hxxps://streamyard.appstore.com[.]mx/installer.sh URL hxxps://slack.apple03cloudstore[.]com/in |
| domain | toria.app | ly motivated threat actors. IOCs Type Indicator URL hxxps://toria[.]app/ URL hxxps://warpcast[.]asia/Toria.dmg URL hxxps://stream |
| domain | warpcast.asia | s. IOCs Type Indicator URL hxxps://toria[.]app/ URL hxxps://warpcast[.]asia/Toria.dmg URL hxxps://streamyard.appstore.com[.]mx/instal |
| url | https://docsend.appstore.com[ | /installer.sh URL hxxps://toria.apple03cloudstore[.]com/ C2 hxxps://docsend.appstore.com[.]mx C2 hxxps://toria.apple03cloudstore[.]com Note: IP addre |
| url | https://slack.apple03cloudstore[ | g URL hxxps://streamyard.appstore.com[.]mx/installer.sh URL hxxps://slack.apple03cloudstore[.]com/installer.sh URL hxxps://toria.apple03cloudstore[.]com |
Full article860 words · extracted from gbhackers.com · click to collapse
A newly observed MacSync campaign shows a marked evolution in macOS-focused crimeware, replacing relatively simple AppleScript-driven delivery with layered binary loaders, encrypted modules, cloud-hosted staging, and a persistent backdoor.
Kaspersky first identified the new infection chain in the wild in September 2026, describing it as a significant upgrade for the malware family formerly marketed as Mac.
Earlier samples relied heavily on AppleScript and resembled the AMOS stealer family.
The latest variant instead uses native-looking, universal Mach-O binaries written in Swift and Objective-C, allowing it to run on both Apple Silicon and Intel-based Macs while making analysis and detection more difficult.
The campaign begins with a malicious DMG containing an application bundle masquerading as legitimate or cracked software.
Researchers observed MacSync being distributed as a fake cryptocurrency-wallet application named Toria, promoted through a dedicated website as well as X and Telegram activity.
This reflects a broader targeting strategy aimed at crypto users, developers, and IT professionals whose devices may hold wallets, credentials, source-code access, cloud keys, and enterprise secrets.
Once launched, the initial application checks for the com.apple.quarantine extended attribute and attempts to remove it with xattr -cr.
It then decrypts an embedded URL that leads to the next payload stage. In some samples, the next-stage file sits on attacker-controlled infrastructure.

In another, more unusual case, the malware retrieves a public iCloud calendar file hosted through Apple’s CalDAV service.
The calendar itself is not the initial infection vector. Victims must first download and execute the malicious DMG.
The iCloud calendar is instead abused as an intermediate delivery channel after compromise, demonstrating how attackers can blend malicious content into trusted cloud infrastructure.
MacSync’s downloader launches zsh and pipes the calendar file into the shell line by line. Most calendar content produces invalid-command errors, but malicious commands concealed after the calendar event’s DESCRIPTION: field are eventually processed.
Those commands download a compressed archive from iCloud containing another malicious application bundle, remove its quarantine attributes, apply an ad-hoc signature, and execute it.
The following stages decrypt and unpack payloads in /tmp, remove traces after execution, and create lock files to avoid repeated execution.
Kaspersky said in a report shared with GBhackers, MacSync is a malware-as-a-service operation designed to steal credentials, browser data, cryptocurrency-wallet information, Keychain material, developer configuration files, and other high-value data from macOS systems.
MacSync’s New Infection Chain
One dropper also checks for virtualization through sysctl queries and uses ptrace with PT_DENY_ATTACH to block debugger attachment, raising the cost of sandboxing and dynamic analysis.
The chain then deploys a custom pkgunpack utility that uses Curve25519-based key exchange and AES-GCM to obtain payload-decryption keys from the command-and-control server.
This per-session cryptographic workflow means analysts cannot simply extract a static decryption key from one sample and apply it broadly across the campaign.

The final payloads consist of a Swift-based infostealer and an Objective-C backdoor.
The stealer displays application-specific administrator-password prompts and follows them with a fake macOS warning that the application is corrupted.
Many strings in the stealer (file names, directory names, team IDs, and so on) are XOR-encrypted and stored in static arrays.
It validates entered credentials through the macOS Pluggable Authentication Modules API, a technique previously highlighted in the PamStealer family and one that avoids more familiar command-line validation methods.

MacSync targets browser histories, cookies, saved passwords, wallet-extension data, Telegram artifacts, Keychain files, SSH and cloud configuration files, ZSH and Bash histories, installed-application lists, active processes, and device information.
Its focus on AWS, Kubernetes, Git, SSH, browsers, and cryptocurrency data makes developer workstations especially valuable targets.
The backdoor disguises itself as Finder and establishes persistence through a com.apple.finder.agent LaunchAgent, .zshrc modification, and global Git pre-commit and post-checkout hooks.
It can restore deleted files, suppress user-visible persistence notifications by killing macOS management processes, exfiltrate files, deploy browser extensions, re-collect data, and potentially support browser traffic interception through a component called sn_relay.
MacSync illustrates that macOS malware is moving beyond opportunistic credential theft toward modular, resilient intrusion tooling.
Organizations should block untrusted DMGs, restrict execution of unsigned applications, monitor suspicious use of xattr, zsh, curl, launchctl, and security utilities, and investigate new LaunchAgents, altered shell profiles, and unexpected Git hook changes.
Kaspersky detects the activity as HEUR:Trojan.OSX.MacSync.*, HEUR:Trojan-PSW.OSX.MacSync.*, HEUR:Trojan-Dropper.OSX.MacSync.*, and HEUR:Trojan-Downloader.OSX.MacSync.*.
The campaign’s combination of trusted-cloud abuse, native binaries, evolving cryptography, credential collection, and long-term persistence makes it a clear warning that macOS is now a mature and increasingly attractive platform for financially motivated threat actors.
IOCs
| Type | Indicator |
|---|---|
| URL | hxxps://toria[.]app/ |
| URL | hxxps://warpcast[.]asia/Toria.dmg |
| URL | hxxps://streamyard.appstore.com[.]mx/installer.sh |
| URL | hxxps://slack.apple03cloudstore[.]com/installer.sh |
| URL | hxxps://toria.apple03cloudstore[.]com/ |
| C2 | hxxps://docsend.appstore.com[.]mx |
| C2 | hxxps://toria.apple03cloudstore[.]com |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.