New MacSync macOS Stealer Uses Binary Loaders to Target Crypto Users and Developers

· Original article ↗

Summary

Kaspersky analyzed a new MacSync infection chain using malicious DMG apps, binary droppers and iCloud-hosted content to install a macOS infostealer and backdoor targeting crypto users and developers.

Key points

  • Kaspersky observed the new infection chain in September 2026; victims are lured with fake or disguised apps, including the purported crypto wallet Toria.
  • The malware uses binary droppers and loaders, with Objective-C and Swift payloads; one stage used a public iCloud calendar to deliver commands and another payload.
  • The infostealer seeks browser and wallet data, saved credentials, Keychain files, Telegram data, SSH and cloud-service configurations, command histories, and system information.
  • A backdoor establishes persistence through a LaunchAgent, shell startup configuration, and Git hooks, and can receive commands to collect files or deploy browser extensions and a Ledger wallet replacement.
  • Kaspersky reports anti-debugging and virtual-machine checks, encrypted payloads, and techniques to conceal persistence and hinder forensic analysis.
  • The report provides indicators of compromise and Kaspersky detection verdicts for MacSync-related droppers, downloaders, and stealers.

Article Details

Attack Vectors
  • MacSync is distributed under a malware-as-a-service model, and its first-stage delivery method varies by operator. The article reports distribution through social engineering, ClickFix-style attacks, and applications presented as free, cracked, or new software.
  • A version first observed in September 2026 began with malicious DMG images. One examined application masqueraded as a nonexistent crypto wallet called Toria.
  • One delivery path executed a compiled JXA script that decoded and ran a shell script without writing it to disk. Another used successive binary loaders and droppers, including a downloader that retrieved commands from a public iCloud calendar and an archive from iCloud.
  • Later stages downloaded and decrypted an infostealer and a backdoor. The infostealer solicited the user's administrator password and collected browser, crypto wallet, Telegram, keychain, system, and configuration data.
  • The backdoor received commands over HTTP. Its supported commands included deploying a browser extension, replacing an installed Ledger wallet with a version from the server, and collecting files again. The researchers could not determine the contents of the scripts supplied for those commands.
Defensive Notes
  • Kaspersky reports detection verdicts HEUR:Trojan.OSX.MacSync.*, HEUR:Trojan-PSW.OSX.MacSync.*, HEUR:Trojan-Dropper.OSX.MacSync.*, and HEUR:Trojan-Downloader.OSX.MacSync.*.
  • The examined infection chain removed macOS quarantine attributes and applied ad-hoc signatures to downloaded applications.
  • Observed persistence locations included a LaunchAgent named com.apple.finder.agent, commands in .ZSHRC and global GIT hooks, and, for some backdoor launches, Login Items. The .repair-run script could restore missing backdoor files from a backup.
  • The backdoor's live_browser command downloaded and executed sn_relay if absent, but the researchers said its contents and purpose remained unknown.

Indicators of compromise

TypeIndicatorContext
MD500d12d842596bf5ee1805effb4571d30MacSync stage-six script hash.
MD526a0f7cdb9f7dc5ace9a40af825b1538MacSync stage-one loader hash.
MD52d69812584269699fade26622e6490c5MacSync stage-one loader hash.
MD53ded1d71a822b53b12c3b67bcaf633f5Malicious stage-two calendar hash.
MD53deeed48fd38f22e369f5c3092bd68a1MacSync stage-four dropper hash.
MD54203ec932bfcc0907f91732440d6d997MacSync stage-three dropper hash.
MD56791dad263cac6d63ebba6a4b57e7d71MacSync stage-one loader hash.
MD57212229c85852c3bffaf9740002b2f39Auxiliary .repair-run persistence script hash.
MD5781ce50001d4b449600afa347c9b0208MacSync stage-three dropper hash.
MD57df1049cbd56c0bfa4a3364a379b4c2cMacSync stage-one loader hash.
MD58dc8561349d144d4661bc66f2ec49f9fAuxiliary autorun tool hash.
MD58e84b01d5ac9624f0b181ade0e737193MacSync stage-three dropper hash.
MD5980e2134679bc0c609f7659882883d77MacSync stage-three dropper hash.
MD59a0043d900a9ac78c886c59c9a328fd0MacSync stage-six script hash.
MD59f15fe9c4415cd668334339f705b94d8MacSync stage-one loader hash.
MD5c53d0ea45dbc622afb7f16ea3eec78bcAuxiliary .repair-run persistence script hash.
MD5eb760d5c88f13f7ee0f8f86ba3407123MacSync stage-three dropper hash.
MD5f97d24212fa6a21be0c4d211e10f044cMacSync stage-five script hash.
MD5f9f70096aabb4d22a6657014f4853a53MacSync stage-three dropper hash.
MD5fb90887592655a8c989e443c640167aaMacSync stage-one loader hash.
MD5fc3ba5ed282d77127efd0b0f2403531bAuxiliary .repair-run persistence script hash.
URLhxxp[:]//caldav[.]icloud[.]com/published/2/MTk1NDMwMDMzNTUxOTU0M1aHCZ-nMxiyGzBTzPiodOf44DtKJ6PpjftAG28_ui2NCYMpL_vu4pF4ddsJ8ysg0QI7pR0VEIEbZYdilVZRw08Specific public iCloud calendar URL used to deliver next-stage downloader commands.
URLhxxps[:]//caldav[.]icloud[.]com/published/2/MTk1NDMwMDMzNTUxOTU0M1aHCZ-nMxiyGzBTzPiodOf44DtKJ6PpjftAG28_ui2NCYMpL_vu4pF4ddsJ8ysg0QI7pR0VEIEbZYdilVZRw08Specific public iCloud calendar URL listed as a malicious stage-two indicator.
URLhxxps[:]//docsend[.]appstore[.]com[.]mxMacSync command-and-control server URL listed in the article's indicators.
URLhxxps[:]//docsend[.]appstore[.]com[.]mx/dcc737d157ef4271/CoreUpdate[.]pkg[.]encEncrypted malicious package URL listed in the article's indicators.
URLhxxps[:]//docsend[.]appstore[.]com[.]mx/dcc737d157ef4271/Helper[.]pkg[.]encEncrypted malicious package URL listed in the article's indicators.
URLhxxps[:]//docsend[.]appstore[.]com[.]mx/dcc737d157ef4271/stage2[.]encEncrypted MacSync stage-two payload URL.
URLhxxps[:]//gateway[.]icloud[.]com/caldav/1_MTk1NDMwMDMzNTUxOTU0M0pybtJB186GzhogprwCQUjY3oZNiDFHH8WVo6bmgUtI/attach/4GE4TKNBTGAYDGMZVGUYTSNJUGOAALDAFMDOJBGWNUCYJLZRNDCLCO2YMQ3I64RLGMNXVG3KYBPWQOGYIEI7MPBDDYHECFDYVENTXIYFNDCPOVRMCTYI236RCYZAE63V5U3RTUYGUMO2CO7PKCLWMCXE73M7OPTHSGRWH5DXQ4PCUQU4ELZTLW54JSTK2H7VQ6PD26WOA2R7PPIQ6RTJWDEWP34U3HB4YWMXXC6EJ6PKWILSPYRSDEVY6QGMWSIUN6PR5W35KO3D4QZE7CFPUVBAEKI/Loader[.]app[.]tar[.]gz/YXR0YWNoYXR0YWNoYXR0YRhrE8mQ0E-b_dTUSGStQgTQ0ULFxCanei3Ke-EuEyQLSpecific iCloud-hosted malicious Loader.app.tar.gz attachment URL.
URLhxxps[:]//slack[.]apple03cloudstore[.]com/installer[.]shMalicious installer script URL listed in the article's indicators.
URLhxxps[:]//streamyard[.]appstore[.]com[.]mx/installer[.]shMalicious installer script URL listed in the article's indicators.
URLhxxps[:]//toria[.]app/Web page for the nonexistent Toria crypto wallet application used to disguise MacSync.
URLhxxps[:]//toria[.]apple03cloudstore[.]com/Threat-associated Toria URL listed in the article's indicators.
URLhxxps[:]//toria[.]apple03cloudstore[.]com/e3c1a6b00bc31e14/stage2[.]encEncrypted MacSync stage-two payload URL.
URLhxxps[:]//waaako[.]appstore[.]com[.]mx/installer[.]shMalicious installer script URL listed in the article's indicators.
URLhxxps[:]//warpcast[.]asia/Toria[.]dmgMalicious DMG delivery URL listed in the article's indicators.

MITRE ATT&CK

T1027 · Obfuscated Files or InformationThe malware stores encrypted URLs, configuration, strings, and payloads, including XOR-encrypted data in executable overlays.T1036.005 · Match Legitimate Resource Name or LocationThe backdoor disguises itself as the Finder application.T1041 · Exfiltration Over C2 ChannelA script uploads data collected by the infostealer to the C2 server in PUT requests, using 90-megabyte chunks.T1059.002 · AppleScriptThe backdoor extracts base64-encoded AppleScript supplied in C2 responses and executes it.T1059.004 · Unix ShellDownloaders and scripts pass commands to zsh and execute shell-script payloads.T1059.007 · JavaScriptOne malicious DMG contains a compiled JXA script that decodes and launches a shell script.T1070.004 · File DeletionModules remove temporary files and their own logs after completing their tasks.T1071.001 · Web ProtocolsThe backdoor exchanges HTTP requests and JSON responses with its C2 server to receive commands and report status.T1105 · Ingress Tool TransferDownloaders retrieve subsequent malicious scripts, application archives, and modules; the backdoor can also download an extension or sn_relay.T1140 · Deobfuscate/Decode Files or InformationSuccessive stages decrypt and unpack encrypted scripts and executables before running them.T1204.002 · Malicious FileA victim launching an application from the malicious DMG starts the examined infection chain.T1497.001 · System ChecksA dropper checks kern.hv_vmm_present and the CPU brand string for signs that it is running in a virtual machine.T1539 · Steal Web Session CookieThe infostealer collects browser cookies.T1543.001 · Launch AgentThe backdoor establishes persistence through a LaunchAgent named com.apple.finder.agent.T1546.004 · Unix Shell Configuration ModificationThe malware adds a command to .ZSHRC to run its .repair-run script when ZSH starts.T1547.015 · Login ItemsFor macOS versions older than 13.0, a backdoor helper adds its executable to Login Items.T1553.001 · Gatekeeper BypassThe infection chain removes com.apple.quarantine attributes from applications and applies ad-hoc signatures before execution.T1555.003 · Credentials from Web BrowsersThe infostealer collects saved browser logins and passwords; its disabled keychain-access feature also contains examples targeting browser secrets.T1560.001 · Archive via UtilityThe infostealer's collected data is compressed into a .TAR.GZ archive before upload.T1622 · Debugger EvasionA dropper sets PT_DENY_ATTACH with ptrace to prevent a debugger from attaching.

Malware

Vendors

Products

Tools

Industries

Related Articles