A new MacSync malware-as-a-service campaign targets macOS cryptocurrency users and developers with trojanized DMG applications, binary loaders, and droppers. Originally advertised as Mac.c in 2025, the stealer has progressed from AppleScript payloads to Swift and Objective-C binaries and now uses Apple iCloud Calendar and file-hosting infrastructure to retrieve subsequent payloads.
MacSync collects browser and cryptocurrency-wallet data, credentials, Keychain-related material, Telegram data, cloud and developer configuration files, system details, and shell histories. It persists through LaunchAgents, modified ZSH settings, global Git hooks, Login Items, and restoration scripts while suppressing user notifications; its backdoor can receive C2 tasks to install browser extensions, replace Ledger wallet software, repeat collection, and potentially intercept browser traffic.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
Researchers first observed an updated MacSync campaign using malicious DMG application bundles, binary loaders and droppers, and iCloud Calendar and file-hosting infrastructure to deliver later-stage payloads. The campaign included Toria cryptocurrency-wallet impersonation and deployed an infostealer and Objective-C backdoor with extensive persistence and data-theft capabilities.
The macOS information and cryptocurrency stealer was advertised under the name Mac.c on dark-web forums before its developers renamed it MacSync.
A Gurucul threat-research report documented MacSync persistence through LaunchAgents and Git hooks in addition to ZSHRC modification, along with AES/ECDH Curve25519 use, anti-debugging, and in-memory execution. The report published 21 MD5 hashes and malicious URL indicators tied to MacSync infrastructure and payload delivery.
A Huntress-documented MacSync Stealer/RAT intrusion temporarily modified the victim's ~/.zshrc so that a Base64-wrapped curl | zsh command would run when the victim next opened an interactive zsh Terminal session. The exact command was not published.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 56 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
11 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcecommunity.gurucul.com
Open sourcehelpnetsecurity.com
Open sourcecybersecuritynews.com
Open sourcesecurelist.ru
Open sourcesecurelist.com
Open sourcedfir.ch
Open sourcetheevilbit.github.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.