Top Highlights
- MacSync has shifted from script-based to binary payload delivery, using Objective-C and Swift modules, and exploits Apple infrastructure like iCloud for command delivery.
- The malware employs complex, multi-stage infection chains involving malicious DMG images, encrypted payloads, and self-made key exchange utilities, enabling stealthy, in-memory execution.
- It targets developer and crypto community users, harvesting extensive system, browser, and crypto wallet data, and deploying persistent backdoors that manipulate keychains and system startup items.
The Threat, Attack Techniques, and Targets
The new MacSync version is a macOS malware family that steals crypto and other sensitive data. It started in 2025 and evolved rapidly. Instead of using simple scripts, attackers now deliver binary modules written in Objective-C and Swift. They use malicious DMG images to infect devices starting with compiled JavaScript for Automation (JXA) scripts. The infection chain involves loaders, droppers, and encrypted scripts. The malware can use iCloud to deliver payloads and maintains persistence via LaunchAgents and code injection. Targets are mainly developers, crypto enthusiasts, and IT users, as they aim to steal browser data, crypto wallet info, system details, and more. Attackers often disguise malware as cracked apps or fake crypto wallets to trick users into opening malicious files or clicking links.
Impact, Security Implications, and Remediation Guidance
The impact includes theft of sensitive personal and organizational data, potential compromise of developer and crypto accounts, and increased risk of further system intrusion. The malware’s complex infection chain and use of sophisticated encryption make detection difficult. It also maintains stealth by deleting traces and disguising itself as legitimate applications like Finder. Security implications are serious, especially since high-value targets like developers and crypto users are involved. If you suspect infection, it is best to consult your security vendor or authoritative sources for specific remediation steps. General guidance includes updating macOS, using trusted sources for downloads, and monitoring for unusual activity. Since detailed remediation instructions are not provided here, obtain advice from the relevant vendor or cybersecurity authority.
Discover More Technology Insights
Learn how the Internet of Things (IoT) is transforming everyday life.
Access comprehensive resources on technology by visiting Wikipedia.
ThreatIntel-V1
