New MacSync Version Targets Crypto Enthusiasts with Advanced Infection Techniques

Published:

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

The emergence of the MacSync malware family marks a significant evolution in the landscape of cyber threats targeting macOS users, particularly those involved in cryptocurrency and information technology. Initially introduced on the dark web in 2025 as Mac.c, the malware has since been rebranded as MacSync and has undergone substantial enhancements, including the integration of a backdoor module. The latest version, identified in September 2026, showcases a sophisticated infection chain that diverges markedly from its predecessors, as detailed in a recent report by Kaspersky.

One of the most notable changes in this iteration is the shift from script-based droppers to binary payloads, with the primary malicious components now developed in Objective-C and Swift. This transition not only increases the complexity of the malware but also enhances its stealth and effectiveness. The developers have adopted a malware-as-a-service (MaaS) model, allowing for varied delivery methods that include social engineering tactics and the distribution of counterfeit applications, such as a fictitious crypto wallet named Toria, which was promoted on platforms like X and Telegram. This strategy underscores the malware’s targeting of crypto enthusiasts and developers, who are often prime targets for information theft.

Technical Details

Infection Chain

The infection process begins with malicious DMG images that contain the payload. Within a single campaign, researchers observed two distinct methods for delivering the infostealer and backdoor modules. In one approach, a compiled JXA script within the DMG decodes a shell script and executes it directly in memory, while in another, the same script is introduced later in the infection process after a series of droppers and loaders have been activated. This complexity is indicative of a more advanced operational methodology.

Throughout the infection stages, MacSync exhibits consistent behaviors, such as storing temporary files in the /tmp directory and removing traces of its activities upon completion. The binary files are formatted in FAT Mach-O, ensuring compatibility with both Apple and Intel processors. This adaptability is crucial for maximizing the malware’s reach across different macOS environments.

Loader, Calendar, and Two Simple Droppers

The latest version of MacSync employs a two-stage delivery mechanism involving a downloader script that retrieves the next-stage payload from a command-and-control (C2) server. In some instances, this script pointed to a public iCloud calendar, demonstrating the attackers’ innovative use of legitimate services to facilitate malware distribution. The downloader creates an anonymous pipe and executes commands from the calendar, ultimately leading to the download of a .TAR.GZ archive containing the malicious payload.

Once the payload is extracted, it is placed in a temporary directory and executed. This dropper includes anti-debugging measures, checking for virtual machine environments and preventing debuggers from attaching to the process. The payload itself is a shell script encrypted with AES, which further complicates analysis and detection efforts.

Infostealer

The infostealer component of MacSync is designed to collect a wide array of sensitive information, including browser data, crypto wallet credentials, and system configurations. It employs a novel method for password verification using the Pluggable Authentication Modules (PAM) API, a technique that has recently gained traction among macOS malware authors. This approach allows the malware to adapt its interface to mimic legitimate applications, thereby increasing the likelihood of user interaction and credential capture.

Data collected by the infostealer is stored in a hidden directory within the /tmp/ folder, and the malware’s design includes mechanisms for maintaining persistence on the infected system. This includes injecting commands into the .ZSHRC file and creating LaunchAgents that ensure the malware remains active even after system reboots.

Implications

The evolution of the MacSync malware family highlights a concerning trend in the cyber threat landscape, particularly for users in the cryptocurrency and tech sectors. The sophisticated techniques employed by the attackers not only enhance the malware’s effectiveness but also pose significant risks to both individual users and corporate environments. As the malware continues to evolve, it is imperative for users to remain vigilant and adopt robust security measures to mitigate the risks associated with such advanced threats.

For further details on this evolving threat, refer to the comprehensive analysis provided by Kaspersky here.

Follow Cyber Warriors Middle East for further cybersecurity features, analysis and insights.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Astrana Health Reports Data Breach Following Social Engineering Attack on Employees

Astrana Health has reported a data breach involving the theft of private and confidential information from its servers, following a social engineering attack that...

CloudSEK Addresses Escalating AI-Driven Cyber Risks in the Middle East

CloudSEK Tackles Rising AI-Driven Cyber Risks in the Middle East Cyber threats in the Middle East are escalating, with state-sponsored groups, ideologically motivated actors, and...

CWME_REVIEW_REQUIRED

CWME_REVIEW_REQUIRED Explore more technology and cybersecurity reporting from Cyber Warriors Middle East.

CISA Unveils Plan to Enhance Quality of Common Vulnerabilities and Exposures Program Amid Rising CVE Submissions

The Cybersecurity and Infrastructure Security Agency (CISA) has released a white paper outlining its strategy to enhance the Common Vulnerabilities and Exposures (CVE) program,...