MacSync is a macOS information-stealing malware family distributed under a malware-as-a-service model. First advertised in 2025 as Mac.c and subsequently renamed, it targets both Intel-based and Apple Silicon Macs. Its collection capabilities and application lures emphasize developers, cryptocurrency users, and other IT-associated users. Updated variants identified in September 2026 combine a Swift-based infostealer with an Objective-C backdoor, extending credential theft into persistent remote access.
MacSync spreads through ClickFix-style instructions, malicious advertising, fraudulent installation guides, cracked software, and malicious DMG application bundles. Campaigns have impersonated legitimate software and promoted a fictitious cryptocurrency wallet called Toria through social media. Advertising campaigns have also directed users to publicly shared AI-platform pages containing deceptive installation instructions that persuade victims to execute Terminal commands. Multi-stage delivery chains use compiled loaders and droppers, encrypted payloads, and, in some cases, public iCloud Calendar descriptions containing shell commands that retrieve subsequent stages. Evasion measures include removal of quarantine metadata, virtual-machine detection, debugger blocking, in-memory execution, and deletion of temporary artifacts and logs. Module delivery uses Curve25519 key exchange and AES encryption.
The infostealer presents fraudulent administrator-password prompts and validates submitted credentials through macOS Pluggable Authentication Modules. It collects browser history, saved passwords, session cookies, cryptocurrency-wallet application and extension data, Telegram data and sessions, macOS login credentials, Keychain data, and files. Developer-oriented collection includes SSH keys, cloud credentials, AWS and Kubernetes configurations, Git configurations, and shell histories. It also gathers hardware details, installed applications, and running-process information, and exfiltrates collected data to attacker-controlled infrastructure.
The backdoor masquerades as Finder and maintains persistence through LaunchAgents, shell startup configuration changes, and global Git hooks. Restoration routines can replace deleted components, while termination of macOS notification processes suppresses persistence-related alerts. Remote capabilities include execution of attacker-supplied AppleScript, additional file collection and upload, deployment of browser extensions, and replacement of installed Ledger wallet software with an attacker-supplied version.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
"Threat Details and IOCs Malware: Mac.c, MacSync, MacSync Stealer CVEs: CVE-2023-31290"
38 distinct techniques documented for this family, organized by ATT&CK tactic.
Vecteurs observés : ... Scripts JXA compilés ou chaînes de droppers/loaders.
«закрепляется в системе... через... .zshrc». | «загрузчик передавал его содержимое в zsh, а команды, скрытые после поля DESCRIPTION, загружали следующий .app-бандл».
«приложение... извлекает зашифрованный URL следующего этапа»; «Один извлекает зашифрованный бинарник».
Le malware se déguise en applications populaires gratuites ou crackées; la persistance comprend com.apple.finder.agent et $HOME/Library/Application Support/System.
Les droppers déchiffrent des exécutables et scripts AES-CBC; le script principal utilise ECDH Curve25519 + AES-GCM pour les modules finaux.
«второй проверяет, не запущен ли он в виртуальной машине».
Le second dropper inclut des protections anti-débogage (kern.hv_vmm_present, machdep.cpu.brand_string, PT_DENY_ATTACH).
«подменять установленный кошелек Ledger версией с сервера атакующих».
«Стилер по-прежнему стремится выманить у пользователя пароль администратора... MacSync обращается к API... PAM... для проверки учетных данных».
Demande le mot de passe administrateur via une fausse fenêtre système [et] utilise l’API PAM ... pour vérifier le mot de passe.
«MacSync похищает... конфигурации SSH, AWS, Kubernetes и Git».
Données collectées : wallets crypto, données Telegram, informations système, fichiers de configuration, historiques ZSH/Bash et photo de profil.
«Стилер по-прежнему стремится выманить у пользователя пароль администратора... MacSync обращается к API... PAM... для проверки учетных данных».
The infection chain includes “abuse of iCloud Calendar for payload delivery.”
«ссылка вела на публичный календарь iCloud: загрузчик передавал его содержимое в zsh, а команды, скрытые после поля DESCRIPTION, загружали следующий .app-бандл».
400 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
147 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a comparison to PamStealer. Uses fake system password requests and has cryptocurrency wallet application-swapping features involving Ledger and Trezor. No operational connection to PamStealer is established.
Referenced only as a comparison: MacSync campaigns reportedly combine data theft and remote-access capabilities.
Mac malware mentioned only as a comparison because its campaigns combine information theft with remote access. The reference does not establish a relationship between MacSync and CloudSyncD.
macOS-инфостилер и бэкдор, ориентированный на кражу данных браузеров, криптокошельков, Telegram, Keychain, учетных данных устройства, а также SSH, AWS, Kubernetes и Git-конфигураций. Запрашивает пароль администратора и проверяет его через PAM API. Бэкдор маскируется под Finder, обеспечивает закрепление через LaunchAgent, .zshrc и глобальные Git-хуки, может загружать расширения браузера, подменять Ledger-кошелек и собирать файлы. Новая реализация использует Swift для стилера и Objective-C для бэкдора.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.