New MacSync macOS Stealer Uses Binary Loaders to Target Crypto Users and Developers

Summary
Kaspersky analyzed a new MacSync infection chain using malicious DMG apps, binary droppers and iCloud-hosted content to install a macOS infostealer and backdoor targeting crypto users and developers.
Key points
- Kaspersky observed the new infection chain in September 2026; victims are lured with fake or disguised apps, including the purported crypto wallet Toria.
- The malware uses binary droppers and loaders, with Objective-C and Swift payloads; one stage used a public iCloud calendar to deliver commands and another payload.
- The infostealer seeks browser and wallet data, saved credentials, Keychain files, Telegram data, SSH and cloud-service configurations, command histories, and system information.
- A backdoor establishes persistence through a LaunchAgent, shell startup configuration, and Git hooks, and can receive commands to collect files or deploy browser extensions and a Ledger wallet replacement.
- Kaspersky reports anti-debugging and virtual-machine checks, encrypted payloads, and techniques to conceal persistence and hinder forensic analysis.
- The report provides indicators of compromise and Kaspersky detection verdicts for MacSync-related droppers, downloaders, and stealers.
Article Details
- Attack Vectors
- MacSync is distributed under a malware-as-a-service model, and its first-stage delivery method varies by operator. The article reports distribution through social engineering, ClickFix-style attacks, and applications presented as free, cracked, or new software.
- A version first observed in September 2026 began with malicious DMG images. One examined application masqueraded as a nonexistent crypto wallet called Toria.
- One delivery path executed a compiled JXA script that decoded and ran a shell script without writing it to disk. Another used successive binary loaders and droppers, including a downloader that retrieved commands from a public iCloud calendar and an archive from iCloud.
- Later stages downloaded and decrypted an infostealer and a backdoor. The infostealer solicited the user's administrator password and collected browser, crypto wallet, Telegram, keychain, system, and configuration data.
- The backdoor received commands over HTTP. Its supported commands included deploying a browser extension, replacing an installed Ledger wallet with a version from the server, and collecting files again. The researchers could not determine the contents of the scripts supplied for those commands.
- Defensive Notes
- Kaspersky reports detection verdicts HEUR:Trojan.OSX.MacSync.*, HEUR:Trojan-PSW.OSX.MacSync.*, HEUR:Trojan-Dropper.OSX.MacSync.*, and HEUR:Trojan-Downloader.OSX.MacSync.*.
- The examined infection chain removed macOS quarantine attributes and applied ad-hoc signatures to downloaded applications.
- Observed persistence locations included a LaunchAgent named com.apple.finder.agent, commands in .ZSHRC and global GIT hooks, and, for some backdoor launches, Login Items. The .repair-run script could restore missing backdoor files from a backup.
- The backdoor's live_browser command downloaded and executed sn_relay if absent, but the researchers said its contents and purpose remained unknown.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| MD5 | 00d12d842596bf5ee1805effb4571d30 | MacSync stage-six script hash. |
| MD5 | 26a0f7cdb9f7dc5ace9a40af825b1538 | MacSync stage-one loader hash. |
| MD5 | 2d69812584269699fade26622e6490c5 | MacSync stage-one loader hash. |
| MD5 | 3ded1d71a822b53b12c3b67bcaf633f5 | Malicious stage-two calendar hash. |
| MD5 | 3deeed48fd38f22e369f5c3092bd68a1 | MacSync stage-four dropper hash. |
| MD5 | 4203ec932bfcc0907f91732440d6d997 | MacSync stage-three dropper hash. |
| MD5 | 6791dad263cac6d63ebba6a4b57e7d71 | MacSync stage-one loader hash. |
| MD5 | 7212229c85852c3bffaf9740002b2f39 | Auxiliary .repair-run persistence script hash. |
| MD5 | 781ce50001d4b449600afa347c9b0208 | MacSync stage-three dropper hash. |
| MD5 | 7df1049cbd56c0bfa4a3364a379b4c2c | MacSync stage-one loader hash. |
| MD5 | 8dc8561349d144d4661bc66f2ec49f9f | Auxiliary autorun tool hash. |
| MD5 | 8e84b01d5ac9624f0b181ade0e737193 | MacSync stage-three dropper hash. |
| MD5 | 980e2134679bc0c609f7659882883d77 | MacSync stage-three dropper hash. |
| MD5 | 9a0043d900a9ac78c886c59c9a328fd0 | MacSync stage-six script hash. |
| MD5 | 9f15fe9c4415cd668334339f705b94d8 | MacSync stage-one loader hash. |
| MD5 | c53d0ea45dbc622afb7f16ea3eec78bc | Auxiliary .repair-run persistence script hash. |
| MD5 | eb760d5c88f13f7ee0f8f86ba3407123 | MacSync stage-three dropper hash. |
| MD5 | f97d24212fa6a21be0c4d211e10f044c | MacSync stage-five script hash. |
| MD5 | f9f70096aabb4d22a6657014f4853a53 | MacSync stage-three dropper hash. |
| MD5 | fb90887592655a8c989e443c640167aa | MacSync stage-one loader hash. |
| MD5 | fc3ba5ed282d77127efd0b0f2403531b | Auxiliary .repair-run persistence script hash. |
| URL | hxxp[:]//caldav[.]icloud[.]com/published/2/MTk1NDMwMDMzNTUxOTU0M1aHCZ-nMxiyGzBTzPiodOf44DtKJ6PpjftAG28_ui2NCYMpL_vu4pF4ddsJ8ysg0QI7pR0VEIEbZYdilVZRw08 | Specific public iCloud calendar URL used to deliver next-stage downloader commands. |
| URL | hxxps[:]//caldav[.]icloud[.]com/published/2/MTk1NDMwMDMzNTUxOTU0M1aHCZ-nMxiyGzBTzPiodOf44DtKJ6PpjftAG28_ui2NCYMpL_vu4pF4ddsJ8ysg0QI7pR0VEIEbZYdilVZRw08 | Specific public iCloud calendar URL listed as a malicious stage-two indicator. |
| URL | hxxps[:]//docsend[.]appstore[.]com[.]mx | MacSync command-and-control server URL listed in the article's indicators. |
| URL | hxxps[:]//docsend[.]appstore[.]com[.]mx/dcc737d157ef4271/CoreUpdate[.]pkg[.]enc | Encrypted malicious package URL listed in the article's indicators. |
| URL | hxxps[:]//docsend[.]appstore[.]com[.]mx/dcc737d157ef4271/Helper[.]pkg[.]enc | Encrypted malicious package URL listed in the article's indicators. |
| URL | hxxps[:]//docsend[.]appstore[.]com[.]mx/dcc737d157ef4271/stage2[.]enc | Encrypted MacSync stage-two payload URL. |
| URL | hxxps[:]//gateway[.]icloud[.]com/caldav/1_MTk1NDMwMDMzNTUxOTU0M0pybtJB186GzhogprwCQUjY3oZNiDFHH8WVo6bmgUtI/attach/4GE4TKNBTGAYDGMZVGUYTSNJUGOAALDAFMDOJBGWNUCYJLZRNDCLCO2YMQ3I64RLGMNXVG3KYBPWQOGYIEI7MPBDDYHECFDYVENTXIYFNDCPOVRMCTYI236RCYZAE63V5U3RTUYGUMO2CO7PKCLWMCXE73M7OPTHSGRWH5DXQ4PCUQU4ELZTLW54JSTK2H7VQ6PD26WOA2R7PPIQ6RTJWDEWP34U3HB4YWMXXC6EJ6PKWILSPYRSDEVY6QGMWSIUN6PR5W35KO3D4QZE7CFPUVBAEKI/Loader[.]app[.]tar[.]gz/YXR0YWNoYXR0YWNoYXR0YRhrE8mQ0E-b_dTUSGStQgTQ0ULFxCanei3Ke-EuEyQL | Specific iCloud-hosted malicious Loader.app.tar.gz attachment URL. |
| URL | hxxps[:]//slack[.]apple03cloudstore[.]com/installer[.]sh | Malicious installer script URL listed in the article's indicators. |
| URL | hxxps[:]//streamyard[.]appstore[.]com[.]mx/installer[.]sh | Malicious installer script URL listed in the article's indicators. |
| URL | hxxps[:]//toria[.]app/ | Web page for the nonexistent Toria crypto wallet application used to disguise MacSync. |
| URL | hxxps[:]//toria[.]apple03cloudstore[.]com/ | Threat-associated Toria URL listed in the article's indicators. |
| URL | hxxps[:]//toria[.]apple03cloudstore[.]com/e3c1a6b00bc31e14/stage2[.]enc | Encrypted MacSync stage-two payload URL. |
| URL | hxxps[:]//waaako[.]appstore[.]com[.]mx/installer[.]sh | Malicious installer script URL listed in the article's indicators. |
| URL | hxxps[:]//warpcast[.]asia/Toria[.]dmg | Malicious DMG delivery URL listed in the article's indicators. |
MITRE ATT&CK
T1027 · Obfuscated Files or InformationThe malware stores encrypted URLs, configuration, strings, and payloads, including XOR-encrypted data in executable overlays.T1036.005 · Match Legitimate Resource Name or LocationThe backdoor disguises itself as the Finder application.T1041 · Exfiltration Over C2 ChannelA script uploads data collected by the infostealer to the C2 server in PUT requests, using 90-megabyte chunks.T1059.002 · AppleScriptThe backdoor extracts base64-encoded AppleScript supplied in C2 responses and executes it.T1059.004 · Unix ShellDownloaders and scripts pass commands to zsh and execute shell-script payloads.T1059.007 · JavaScriptOne malicious DMG contains a compiled JXA script that decodes and launches a shell script.T1070.004 · File DeletionModules remove temporary files and their own logs after completing their tasks.T1071.001 · Web ProtocolsThe backdoor exchanges HTTP requests and JSON responses with its C2 server to receive commands and report status.T1105 · Ingress Tool TransferDownloaders retrieve subsequent malicious scripts, application archives, and modules; the backdoor can also download an extension or sn_relay.T1140 · Deobfuscate/Decode Files or InformationSuccessive stages decrypt and unpack encrypted scripts and executables before running them.T1204.002 · Malicious FileA victim launching an application from the malicious DMG starts the examined infection chain.T1497.001 · System ChecksA dropper checks kern.hv_vmm_present and the CPU brand string for signs that it is running in a virtual machine.T1539 · Steal Web Session CookieThe infostealer collects browser cookies.T1543.001 · Launch AgentThe backdoor establishes persistence through a LaunchAgent named com.apple.finder.agent.T1546.004 · Unix Shell Configuration ModificationThe malware adds a command to .ZSHRC to run its .repair-run script when ZSH starts.T1547.015 · Login ItemsFor macOS versions older than 13.0, a backdoor helper adds its executable to Login Items.T1553.001 · Gatekeeper BypassThe infection chain removes com.apple.quarantine attributes from applications and applies ad-hoc signatures before execution.T1555.003 · Credentials from Web BrowsersThe infostealer collects saved browser logins and passwords; its disabled keychain-access feature also contains examples targeting browser secrets.T1560.001 · Archive via UtilityThe infostealer's collected data is compressed into a .TAR.GZ archive before upload.T1622 · Debugger EvasionA dropper sets PT_DENY_ATTACH with ptrace to prevent a debugger from attaching.
Malware
AMOSThe initial versions were implemented as AppleScripts and closely resembled the AMOS stealer family, but over time, MacSync developed distinctive features of its own, including a backdoor module.Mac.cFirst advertised on the dark web in 2025 as Mac.c, the stealer was later renamed to MacSync by its creators.MacSyncMacSync is a relatively young, rapidly evolving family of crypto/info stealers.Pam StealerThis is a fairly new technique for macOS malware, first observed in the wild in July 2026 in the Pam Stealer family.
Vendors
Products
BraveBrave Safe Storage|Brave|BraveStorage|apple-tool:,apple:,teamid:KL8N8XSYF4Google ChromeChrome Safe Storage|Chrome|ChromeStorage|apple-tool:,apple:,teamid:EQHXZ8M8AViCloudAt one stage of infection, the attackers use iCloud to deliver the nextLedgerdeploy_ledger: replace the installed Ledger wallet with the version from the server.macOSThis directory doesn’t exist in macOS by default; the script creates it.TelegramFor example, we found MacSync masquerading as a nonexistent crypto wallet app called Toria; the attackers not only created a dedicated web page for it but also promoted it on X and Telegram: