MacSync under the microscope: new delivery methods and a new payload

Executive Summary

Securelist reports a new iteration of the MacSync malware, a macOS stealer that now includes a backdoor module aimed at crypto enthusiasts and developers. The update introduces novel delivery mechanisms and a redesigned payload, enhancing persistence and data exfiltration capabilities. Analysts note the threat’s focus on cryptocurrency wallets and development tools, expanding its target set beyond typical financial victims.


Intelligence Metadata - Source Publisher: Securelist - Published Date: 2026-09-24T10:00:21+00:00 - Category: malware

Original Description: We look at a new version of the MacSync macOS stealer with a backdoor module that targets crypto enthusiasts and developers.

"The real measure of your wealth is how much youd be worth if you lost all your money."

— Unknown
Source: Securelist