New MacSync Malware Turns macOS Apps Into Tools for Crypto and Password Theft
MacSync returned on macOS via fake wallet apps that steal passwords, crypto wallets, and developer credentials.
Kaspersky's Securelist reported that the MacSync macOS infostealer returned in September 2026 with a multi-stage chain aimed at cryptocurrency users and developers. Campaigns use malicious disk images posing as real apps, including a nonexistent wallet called Toria promoted on social media, and can deliver a Swift stealer plus an HTTP backdoor on Apple Silicon and Intel Macs. The stealer collects browser secrets, Keychain files, wallet data, Telegram information, and SSH, AWS, Kubernetes, and Git configuration. Operators persist through a LaunchAgent, ZSH startup files, and Git hooks; one path hides commands in a public iCloud calendar. No victim count was published.
- Delivery shifted to malicious disk images, including a fake Toria crypto wallet.
- The Swift stealer collects browsers, Keychain, wallets, SSH, AWS, Kubernetes, and Git data.
- Persistence includes a LaunchAgent, ZSH startup settings, and global Git hooks.
- One chain retrieves commands hidden in a public iCloud calendar event.
- Kaspersky identified the chain in September 2026; no victim count was published.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | apple03cloudstore.com | x/installer.sh Installer script location. URL hxxps://slack.apple03cloudstore[.]com/installer.sh Installer script location. URL hxxps://toria |
| domain | appstore.com.mx | Ke-EuEyQL iCloud archive attachment. C2 URL hxxps://docsend.appstore[.]com[.]mx Command-and-control address. C2 URL hxxps://toria.apple |
| domain | com.mx | icious disk-image location. URL hxxps://streamyard.appstore.com[.]mx/installer.sh Installer script location. URL hxxps://slack |
| domain | icloud.com | /Helper.pkg.enc Encrypted helper package. URL hxxp://caldav.icloud[.]com/published/2/MTk1NDMwMDMzNTUxOTU0M1aHCZ-nMxiyGzBTzPiodOf44 |
| domain | toria.app | 9d144d4661bc66f2ec49f9f Auxiliary autorun tool. URL hxxps://toria[.]app/ Fake wallet website. URL hxxps://warpcast[.]asia/Toria.d |
| domain | warpcast.asia | . URL hxxps://toria[.]app/ Fake wallet website. URL hxxps://warpcast[.]asia/Toria.dmg Malicious disk-image location. URL hxxps://stre |
Full article1,152 words · extracted from cybersecuritynews.com · click to collapse
MacSync, a fast-changing macOS information stealer, has returned with a more complex delivery chain aimed at people who use cryptocurrency and developer tools.
Instead of relying mainly on a pasted Terminal command, the latest activity begins with malicious disk-image files that pose as real applications. Operators can vary delivery between campaigns.
Victims can encounter the malware through fake or cracked software, including a nonexistent crypto wallet application called Toria.
Once opened, the app can strip macOS quarantine attributes, fetch more code, and ultimately install tools built to steal passwords, wallet data, and work-related credentials. Attackers promoted the invented wallet on social media.
Analysts at Securelist identified the new chain in September 2026, noting a clear shift from script-heavy delivery to compiled components written in Swift and Objective-C.
Kaspersky said in a report shared with Cyber Security News (CSN) that the change makes MacSync more flexible while giving attackers more ways to hide activity on both Apple Silicon and Intel Macs. Not every MacSync campaign uses this chain.
.webp)
Stolen browser sessions, cloud keys, SSH settings, source-control data, and wallet material can expose personal accounts and potentially give criminals a route into corporate environments, as earlier reporting on MacSync fake installer attacks has shown. The researchers did not publish a victim count, so the scale of infections remains unclear.
New MacSync Malware Turns macOS Apps
The campaign starts with a malicious DMG containing an application bundle. In one route, it runs a compiled JXA script directly in memory.
In another, a loader follows several droppers before pulling down the final components, a notable evolution from the earlier ClickFix delivery method. Both routes deliver theft and remote-control tools.
One loader recovers an encrypted address and, in at least one case, retrieves a public iCloud calendar. The event hides commands in its description.
Those commands download an archive containing another application, remove its security markings, add an ad-hoc signature, and run it. The use of a public calendar turns an ordinary sharing feature into an unexpected malware delivery step.
.webp)
The later stages decrypt an information stealer and a backdoor. Temporary files and lock files help manage execution, while completed modules erase logs and other traces.
MacSync also checks for virtual machines and blocks debuggers, making investigation harder. They also complicate checks on infected devices. The malware can masquerade as Finder and stay active through a LaunchAgent, ZSH startup settings, and global Git hooks.
Its repair routine restores files and suppresses startup notifications. This persistence matters because removing the first malicious application may not end the intrusion.
Passwords, Wallets, and Developer Data at Risk
The Swift-based stealer asks for the administrator password through a window tailored to the application it is imitating. After a victim responds, it displays a fake damaged-app alert.
It verifies the password through macOS authentication interfaces rather than an older command-line method. The alert makes installation failure seem routine.
It collects browser history, cookies, saved logins, wallet-extension data, Keychain files, Telegram information, and device details.
It also searches configuration files and histories tied to SSH, ZSH, AWS, Kubernetes, and Git, extending its reach into software-development workflows. Such files can hold access details for cloud services or repositories, raising risks beyond the infected Mac.
.webp)
The backdoor communicates over HTTP and can receive commands, upload files, deploy a browser extension, or replace an installed Ledger wallet with a malicious version.
Its live-browser function may enable interception of browser traffic, although researchers could not determine the helper’s precise purpose. Researchers did not have the command scripts themselves.
Users should obtain software only from verified developer sites and avoid free or cracked copies. They should not bypass macOS warnings, paste unverified commands into Terminal, or approve unexpected password prompts.
Teams should investigate unfamiliar startup items, altered Git hooks, and suspicious outbound uploads, applying lessons from MacSync rotating domain activity and signed macOS app abuse.
If exposure is suspected, isolate the Mac, revoke sessions, and replace credentials from a trusted device. Reviewing all persistence points matters before putting the Mac back online.
Indicators of compromise (IoCs):-
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.