MacSync
MacSync is a macOS information-stealing malware family offered under a malware-as-a-service model.
MacSync
Family profile
MacSync is a macOS information-stealing malware family offered under a malware-as-a-service model. First advertised in 2025 as Mac.c, it was subsequently renamed MacSync. It targets both Intel-based and Apple Silicon Macs, with campaigns focused on developers, cryptocurrency users, and other IT-associated users. Distribution methods include ClickFix lures, malicious advertisements, cracked software, and fraudulent applications packaged in DMG disk images. Campaigns have impersonated cryptocurrency wallets and used shared AI-platform pages to persuade users to execute malicious Terminal commands. MacSync has also been deployed in PasteSwitch malvertising activity.
An updated variant observed in September 2026 combines a Swift-based infostealer with an Objective-C backdoor and uses multistage binary loaders and droppers. Some infection chains retrieve shell commands concealed in public iCloud Calendar event descriptions and download subsequent application bundles from iCloud infrastructure. Evasion measures include removal of macOS quarantine metadata, encrypted payload delivery, in-memory execution, virtual-machine checks, debugger blocking, and deletion of temporary artifacts and logs. Module delivery uses Curve25519 key exchange and AES-GCM encryption.
MacSync uses fraudulent administrator-password dialogs and validates captured passwords through macOS authentication interfaces. It collects browser histories, cookies, saved credentials, cryptocurrency-wallet application and extension data, Telegram data and sessions, macOS Keychain files, device credentials, and system information. It also targets SSH keys, cloud and developer configurations, Git and Kubernetes data, and shell-command histories, exfiltrating collected information to attacker infrastructure.
The backdoor masquerades as Finder and establishes persistence through LaunchAgents, shell-startup modifications, and global Git hooks. Restoration routines recover deleted components, while termination of macOS notification processes conceals persistence-related alerts. It can execute attacker-supplied AppleScript, collect and upload additional files, deploy browser extensions, and replace installed Ledger wallet software with an attacker-provided version.
Capabilities
- Credential Theft
- Crypto Theft
- Defense Evasion
- Exfiltration
- Persistence
- Post Exploitation
- Reconnaissance
- Session Hijacking
Samples
Recent samples
2 sandbox samples in the Derp library, newest 2 shown
Exploited software
Vulnerabilities linked to MacSync
1 CVEsMITRE ATT&CK