MacSync macOS stealer uses iCloud calendars and fake wallets
Kaspersky says MacSync, a macOS infostealer, returned in September 2026 with fake wallet apps, iCloud calendar commands, and a persistent backdoor.
In September 2026 Kaspersky documented a new MacSync macOS infostealer campaign that pairs credential and cryptocurrency theft with a persistent backdoor. Reporting describes multi-stage delivery through malicious disk images, including a fake wallet app called Toria promoted on social media—Help Net Security specifies X and Telegram—and, in one chain, commands hidden in a public iCloud calendar event that a downloader feeds to zsh to retrieve an archive and dropper. The stealer collects browser secrets, Keychain data, crypto wallets, Telegram information, and SSH, AWS, and Git material; Cyber Security News and Help Net Security also include Kubernetes configuration, while only Help Net Security says it prompts for an administrator password via the PAM API rather than dscl. Sources describe an Objective-C backdoor that masquerades as Finder, persists through a LaunchAgent, shell startup files, and global Git hooks, and can run AppleScript; BleepingComputer adds browser-extension deployment and replacement of a Ledger wallet app, whereas Cyber Security News refers to a Swift stealer and an HTTP backdoor on both Apple Silicon and Intel. Kaspersky’s initial note also mentions binary payloads and a malware-as-a-service model that later write-ups do not expand, and no outlet published a victim count.
- Kaspersky reported MacSync, a macOS crypto and information stealer with a backdoor module, in the wild in September 2026.
- Delivery includes malicious DMG disk images, notably a fake crypto wallet called Toria promoted on social media (X and Telegram, per Help Net Security); the initial Securelist note also cites new binary payloads and a malware-as-a-service…
- One chain hides next-stage shell commands in a public iCloud calendar event—in the description, or after the DESCRIPTION line—and a downloader passes that text to zsh, which fetches an archive and an app-bundle dropper.
- The stealer collects browser data, Keychain material, crypto wallets, Telegram data, and SSH, AWS, and Git credentials; Cyber Security News and Help Net Security also list Kubernetes configuration.
- Help Net Security says the stealer requests the administrator password through the PAM API, not dscl.
- An Objective-C backdoor disguised as Finder persists via a LaunchAgent, .zshrc or ZSH startup files, and global Git hooks and can run AppleScript; BleepingComputer also says it can deploy browser extensions and replace a Ledger wallet app,…
- No victim count was published.
Coverage timelineoldest first · each row is one article
- · 3d agoMacSync under the microscope: new delivery methods and a new payload
Kaspersky Securelist· 70
MacSync, a crypto/info stealer with a backdoor module, was spotted in the wild in September 2026 with new binary payload delivery methods.
- · 2d agoMacSync malware uses public iCloud calendars to deliver new payloads
BleepingComputer· 61
MacSync macOS infostealer now pulls new payloads from public iCloud calendar events and adds a persistent backdoor.
- · 2d agoNew MacSync Malware Turns macOS Apps Into Tools for Crypto and Password Theft
Cyber Security News· 60