New MacSync Malware Turns macOS Apps Into Tools for Crypto and Password Theft

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


MacSync, a fast-changing macOS information stealer, has returned with a more complex delivery chain aimed at people who use cryptocurrency and developer tools.

Instead of relying mainly on a pasted Terminal command, the latest activity begins with malicious disk-image files that pose as real applications. Operators can vary delivery between campaigns.

Victims can encounter the malware through fake or cracked software, including a nonexistent crypto wallet application called Toria.

Once opened, the app can strip macOS quarantine attributes, fetch more code, and ultimately install tools built to steal passwords, wallet data, and work-related credentials. Attackers promoted the invented wallet on social media.

Analysts at Securelist identified the new chain in September 2026, noting a clear shift from script-heavy delivery to compiled components written in Swift and Objective-C.

Kaspersky said in a report shared with Cyber Security News (CSN) that the change makes MacSync more flexible while giving attackers more ways to hide activity on both Apple Silicon and Intel Macs. Not every MacSync campaign uses this chain.

MacSync masquerading as a nonexistent crypto wallet app called Toria (Source - Securelist)
MacSync masquerading as a nonexistent crypto wallet app called Toria (Source – Securelist)

Stolen browser sessions, cloud keys, SSH settings, source-control data, and wallet material can expose personal accounts and potentially give criminals a route into corporate environments, as earlier reporting on MacSync fake installer attacks has shown. The researchers did not publish a victim count, so the scale of infections remains unclear.

New MacSync Malware Turns macOS Apps

The campaign starts with a malicious DMG containing an application bundle. In one route, it runs a compiled JXA script directly in memory.

In another, a loader follows several droppers before pulling down the final components, a notable evolution from the earlier ClickFix delivery method. Both routes deliver theft and remote-control tools.

One loader recovers an encrypted address and, in at least one case, retrieves a public iCloud calendar. The event hides commands in its description.

Those commands download an archive containing another application, remove its security markings, add an ad-hoc signature, and run it. The use of a public calendar turns an ordinary sharing feature into an unexpected malware delivery step.

Attack chain (Source - Securelist)
Attack chain (Source – Securelist)

The later stages decrypt an information stealer and a backdoor. Temporary files and lock files help manage execution, while completed modules erase logs and other traces.

MacSync also checks for virtual machines and blocks debuggers, making investigation harder. They also complicate checks on infected devices. The malware can masquerade as Finder and stay active through a LaunchAgent, ZSH startup settings, and global Git hooks.

Its repair routine restores files and suppresses startup notifications. This persistence matters because removing the first malicious application may not end the intrusion.

Passwords, Wallets, and Developer Data at Risk

The Swift-based stealer asks for the administrator password through a window tailored to the application it is imitating. After a victim responds, it displays a fake damaged-app alert.

It verifies the password through macOS authentication interfaces rather than an older command-line method. The alert makes installation failure seem routine.

It collects browser history, cookies, saved logins, wallet-extension data, Keychain files, Telegram information, and device details.

It also searches configuration files and histories tied to SSH, ZSH, AWS, Kubernetes, and Git, extending its reach into software-development workflows. Such files can hold access details for cloud services or repositories, raising risks beyond the infected Mac.

Fake stealer pop-up windows (Source - Securelist)
Fake stealer pop-up windows (Source – Securelist)

The backdoor communicates over HTTP and can receive commands, upload files, deploy a browser extension, or replace an installed Ledger wallet with a malicious version.

Its live-browser function may enable interception of browser traffic, although researchers could not determine the helper’s precise purpose. Researchers did not have the command scripts themselves.

Users should obtain software only from verified developer sites and avoid free or cracked copies. They should not bypass macOS warnings, paste unverified commands into Terminal, or approve unexpected password prompts.

Teams should investigate unfamiliar startup items, altered Git hooks, and suspicious outbound uploads, applying lessons from MacSync rotating domain activity and signed macOS app abuse.

If exposure is suspected, isolate the Mac, revoke sessions, and replace credentials from a trusted device. Reviewing all persistence points matters before putting the Mac back online.

Indicators of compromise (IoCs):-

Type Indicator Description
MD5 26a0f7cdb9f7dc5ace9a40af825b1538 Stage one loader.
MD5 2d69812584269699fade26622e6490c5 Stage one loader.
MD5 7df1049cbd56c0bfa4a3364a379b4c2c Stage one loader.
MD5 9f15fe9c4415cd668334339f705b94d8 Stage one loader.
MD5 fb90887592655a8c989e443c640167aa Stage one loader.
MD5 6791dad263cac6d63ebba6a4b57e7d71 Stage one loader.
MD5 3ded1d71a822b53b12c3b67bcaf633f5 Malicious calendar, stage two.
MD5 781ce50001d4b449600afa347c9b0208 Stage three dropper.
MD5 8e84b01d5ac9624f0b181ade0e737193 Stage three dropper.
MD5 980e2134679bc0c609f7659882883d77 Stage three dropper.
MD5 4203ec932bfcc0907f91732440d6d997 Stage three dropper.
MD5 eb760d5c88f13f7ee0f8f86ba3407123 Stage three dropper.
MD5 f9f70096aabb4d22a6657014f4853a53 Stage three dropper.
MD5 3deeed48fd38f22e369f5c3092bd68a1 Stage four dropper.
MD5 f97d24212fa6a21be0c4d211e10f044c Stage five script.
MD5 00d12d842596bf5ee1805effb4571d30 Stage six script.
MD5 9a0043d900a9ac78c886c59c9a328fd0 Stage six script.
MD5 7212229c85852c3bffaf9740002b2f39 Auxiliary repair script.
MD5 c53d0ea45dbc622afb7f16ea3eec78bc Infostealer.
MD5 fc3ba5ed282d77127efd0b0f2403531b Backdoor.
MD5 8dc8561349d144d4661bc66f2ec49f9f Auxiliary autorun tool.
URL hxxps://toria[.]app/ Fake wallet website.
URL hxxps://warpcast[.]asia/Toria.dmg Malicious disk-image location.
URL hxxps://streamyard.appstore.com[.]mx/installer.sh Installer script location.
URL hxxps://slack.apple03cloudstore[.]com/installer.sh Installer script location.
URL hxxps://toria.apple03cloudstore[.]com/ Reported malicious URL.
URL hxxps://waaako.appstore.com[.]mx/installer.sh Installer script location.
URL hxxps://toria.apple03cloudstore[.]com/e3c1a6b00bc31e14/stage2.enc Encrypted stage-two payload.
URL hxxps://docsend.appstore.com[.]mx/dcc737d157ef4271/stage2.enc Encrypted stage-two payload.
URL hxxps://docsend.appstore.com[.]mx/dcc737d157ef4271/CoreUpdate.pkg.enc Encrypted package.
URL hxxps://docsend.appstore.com[.]mx/dcc737d157ef4271/Helper.pkg.enc Encrypted helper package.
URL hxxp://caldav.icloud[.]com/published/2/MTk1NDMwMDMzNTUxOTU0M1aHCZ-nMxiyGzBTzPiodOf44DtKJ6PpjftAG28_ui2NCYMpL_vu4pF4ddsJ8ysg0QI7pR0VEIEbZYdilVZRw08 Calendar URL shown in the infection-chain analysis.
URL hxxps://caldav.icloud[.]com/published/2/MTk1NDMwMDMzNTUxOTU0M1aHCZ-nMxiyGzBTzPiodOf44DtKJ6PpjftAG28_ui2NCYMpL_vu4pF4ddsJ8ysg0QI7pR0VEIEbZYdilVZRw08 Calendar URL listed in the report’s IoCs.
URL hxxps://gateway.icloud[.]com/caldav/1_MTk1NDMwMDMzNTUxOTU0M0pybtJB186GzhogprwCQUjY3oZNiDFHH8WVo6bmgUtI/attach/4GE4TKNBTGAYDGMZVGUYTSNJUGOAALDAFMDOJBGWNUCYJLZRNDCLCO2YMQ3I64RLGMNXVG3KYBPWQOGYIEI7MPBDDYHECFDYVENTXIYFNDCPOVRMCTYI236RCYZAE63V5U3RTUYGUMO2CO7PKCLWMCXE73M7OPTHSGRWH5DXQ4PCUQU4ELZTLW54JSTK2H7VQ6PD26WOA2R7PPIQ6RTJWDEWP34U3HB4YWMXXC6EJ6PKWILSPYRSDEVY6QGMWSIUN6PR5W35KO3D4QZE7CFPUVBAEKI/Loader.app.tar.gz/YXR0YWNoYXR0YWNoYXR0YRhrE8mQ0E-b_dTUSGStQgTQ0ULFxCanei3Ke-EuEyQL iCloud archive attachment.
C2 URL hxxps://docsend.appstore[.]com[.]mx Command-and-control address.
C2 URL hxxps://toria.apple03cloudstore[.]com Command-and-control address.
HTTP access token b8b4b88205a8f594b95a841bc37342898f34cad8a5a9e4a22ce69a31a1208650 Observed value for the X-Upload-Token header.
HTTP access token ff3ab9ef841630364818396f62e696b72aed162cf0b895b6643ef25dad79b51d Observed value for the X-Upload-Token header.
File artifact /tmp/.sys-<16-digit random value> Temporary dropper path pattern.
File artifact /tmp/*.lock Lock-file pattern used to prevent repeat execution.
File artifact .ZSHRC Shell startup file modified for persistence.
File artifact .repair-run Script used to restore backdoor persistence.
Directory $HOME/Library/Application Support/System Backdoor files and backup location.
LaunchAgent com.apple.finder.agent Backdoor persistence name.
Git hook pre-commit Global hook modified for persistence.
Git hook post-checkout Global hook modified for persistence.
Log file $HOME/Library/Logs/.sysnotif-agent.log Backdoor log location.
Archive /tmp/osalogging.zip Archive used by the backdoor’s data-collection command.
File name KcHelper Helper sought by a feature disabled in observed samples.
File name sn_relay Additional backdoor resource whose purpose was not confirmed.
Utility pkgunpack Payload key-generation and decryption utility.
URL path /loader/ Path prefix for a backdoor executable on the C2 server.
URL path /v1/agent/ping Backdoor command-check endpoint.
URL path /v1/agent/refresh Backdoor access-token refresh endpoint.
URL path /v1/asset/<upload_id>/init File-upload initialization endpoint.
URL path /v1/asset/<upload_id> File-upload endpoint.
URL path /v1/agent/<command_status> Command-status telemetry endpoint.

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post New MacSync Malware Turns macOS Apps Into Tools for Crypto and Password Theft appeared first on Cyber Security News.