Infection chains used in one campaign: 2 (Source: Kaspersky, via Help Net Security (Sept. 25, 2026))
A Fake Wallet App Opens the Door
Kaspersky has documented a new variant of MacSync, a family of macOS credential-stealing malware first tracked in 2025 under the name Mac.c. The latest version, spotted in September 2026, spread through a fake crypto wallet app called Toria, promoted on X and Telegram. Malware analyst Sergey Puzan said the operators have moved away from the AppleScript-based tooling earlier MacSync variants borrowed from the AMOS stealer, rebuilding the payload as compiled Swift and Objective-C executables. That shift makes the payload harder to inspect and easier to pass off as legitimate software.
Two Infection Paths, One Hidden Command Channel
Kaspersky found the Toria campaign used two separate infection chains. One decoded and ran a shell script directly in memory without writing it to disk. The other routed victims through a longer sequence of droppers and loaders, one of which decrypted a hidden link to a downloader script. In at least one sample, that link pointed not to an attacker-controlled server but to a public iCloud calendar. The downloader fed the calendar entry into a shell interpreter line by line; the shell treated every line as a broken command until it reached one following a description field, where the real instructions were hidden. Those instructions pulled a further app down from iCloud, and the chain continued through nested droppers that checked for virtual-machine sandboxes and blocked debugging tools before installing the stealer.
Password Theft Borrows a Newer Technique
To capture an administrator password, the malware shows a fake login prompt styled to match the app it is impersonating, then follows up with a bogus notice claiming the app is damaged and offering to delete it. Rather than dscl, the utility most Mac malware uses to validate a stolen password, this version calls Apple's Pluggable Authentication Modules interface directly. Puzan noted that this approach had turned up only once before, in a separate family called Pam Stealer, in July 2026. That timing puts MacSync's use among the earliest known follow-on adoptions of the technique.
What It Takes, and How It Stays
Once running, the stealer pulls a wide range of data off the machine: browser history and stored logins, cryptocurrency wallet extensions, Telegram credentials, the Mac login and Keychain file, and a snapshot of installed software and active processes. Kaspersky also lists SSH, zsh, AWS, Kubernetes and Git configuration files among its targets, along with shell command history and even the user's profile photo. That mix leans toward the credentials a developer or cloud administrator would hold, rather than the accounts a typical consumer-facing stealer goes after.
Persistence Lives Inside the Developer's Own Tooling
The backdoor itself, written in Objective-C, masquerades as the Finder application. Kaspersky found three separate mechanisms wired to bring it back if it is removed: a LaunchAgent called com.apple.finder.agent, a line planted in the .zshrc startup file, and code inserted into the machine's global Git pre-commit and post-checkout hooks — meaning an ordinary git commit or checkout can silently relaunch the malware. A separate helper script rebuilds the backdoor from a stored backup if its files go missing, and the malware shuts down three macOS system processes so the new LaunchAgent never triggers a notification to the user. Kaspersky says the backdoor carries out attacker-issued commands including replacing an installed Ledger hardware wallet app with a malicious version and re-collecting system data; researchers could not fully determine the purpose of one command, named sn_relay, but suspect from its behavior it intercepts browser traffic.
Why This Reaches Beyond One Laptop
MacSync's target list of developers, crypto-industry staff, and adjacent IT roles, combined with its appetite for AWS, Kubernetes, SSH and Git credentials, means one infected laptop can become an entry point into company cloud accounts and source repositories, not just personal wallets. Puzan framed the risk in those terms: compromising a developer's device, he said, creates "expanded opportunities for attackers to further their intrusion" into the corporate systems that device can reach, not just the individual's own accounts.
What to Ask Your Team
For organizations with engineering or crypto-facing teams on macOS, the questions worth putting to a security team are specific. Does endpoint monitoring flag changes to global Git hook files and new LaunchAgents on developer machines, not just user-level ones? Are AWS, Kubernetes or SSH credentials ever left in plaintext config files on laptops that could instead sit behind a credential vault? What is the policy on installing third-party crypto-wallet or trading software on devices that also hold source-code or cloud-admin access? And would current tooling catch a password prompt invoking Keychain or PAM authorization from an app other than Apple's own system dialog?
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Help Net Security.





