Skip to content

MacSync

MacSync is a macOS information-stealing malware family offered under a malware-as-a-service model.

MacSync

Family profile

MacSync is a macOS information-stealing malware family offered under a malware-as-a-service model. First advertised in 2025 as Mac.c, it was subsequently renamed MacSync. It targets both Intel-based and Apple Silicon Macs, with campaigns focused on developers, cryptocurrency users, and other IT-associated users. Distribution methods include ClickFix lures, malicious advertisements, cracked software, and fraudulent applications packaged in DMG disk images. Campaigns have impersonated cryptocurrency wallets and used shared AI-platform pages to persuade users to execute malicious Terminal commands. MacSync has also been deployed in PasteSwitch malvertising activity.

An updated variant observed in September 2026 combines a Swift-based infostealer with an Objective-C backdoor and uses multistage binary loaders and droppers. Some infection chains retrieve shell commands concealed in public iCloud Calendar event descriptions and download subsequent application bundles from iCloud infrastructure. Evasion measures include removal of macOS quarantine metadata, encrypted payload delivery, in-memory execution, virtual-machine checks, debugger blocking, and deletion of temporary artifacts and logs. Module delivery uses Curve25519 key exchange and AES-GCM encryption.

MacSync uses fraudulent administrator-password dialogs and validates captured passwords through macOS authentication interfaces. It collects browser histories, cookies, saved credentials, cryptocurrency-wallet application and extension data, Telegram data and sessions, macOS Keychain files, device credentials, and system information. It also targets SSH keys, cloud and developer configurations, Git and Kubernetes data, and shell-command histories, exfiltrating collected information to attacker infrastructure.

The backdoor masquerades as Finder and establishes persistence through LaunchAgents, shell-startup modifications, and global Git hooks. Restoration routines recover deleted components, while termination of macOS notification processes conceals persistence-related alerts. It can execute attacker-supplied AppleScript, collect and upload additional files, deploy browser extensions, and replace installed Ledger wallet software with an attacker-provided version.

Capabilities

  • Credential Theft
  • Crypto Theft
  • Defense Evasion
  • Exfiltration
  • Persistence
  • Post Exploitation
  • Reconnaissance
  • Session Hijacking

Samples

Recent samples

2 sandbox samples in the Derp library, newest 2 shown

Exploited software

Vulnerabilities linked to MacSync

1 CVEs

MITRE ATT&CK

MacSync in ATT&CK

82 distinct techniques

Techniques

82 techniques
T1547.015 Login Items T1204.002 Malicious File T1562.001 Disable or Modify Tools T1027 Obfuscated Files or Information T1056 Input Capture T1040 Network Sniffing T1574 Hijack Execution Flow T1546 Event Triggered Execution T1497 Virtualization/Sandbox Evasion T1560 Archive Collected Data T1555.001 Keychain T1552.001 Credentials In Files T1102.001 Dead Drop Resolver T1573 Encrypted Channel T1552.004 Private Keys T1555.003 Credentials from Web Browsers T1036 Masquerading T1176 Software Extensions T1059.004 Unix Shell T1102 Web Service T1140 Deobfuscate/Decode Files or Information T1543.001 Launch Agent T1552.005 Cloud Instance Metadata API T1036.005 Match Legitimate Resource Name or Location T1552.003 Shell History T1056.002 GUI Input Capture T1059.002 AppleScript T1539 Steal Web Session Cookie T1553.001 Gatekeeper Bypass T1573.001 Symmetric Cryptography T1497.001 System Checks T1041 Exfiltration Over C2 Channel T1560.001 Archive via Utility T1566 Phishing T1546.004 Unix Shell Configuration Modification T1622 Debugger Evasion T1620 Reflective Code Loading T1005 Data from Local System T1082 System Information Discovery T1070.004 File Deletion T1037.004 RC Scripts T1105 Ingress Tool Transfer T1059.007 JavaScript T1071.001 Web Protocols T1070.001 Clear Windows Event Logs T1555 Credentials from Password Stores T1204 User Execution T1074.001 Local Data Staging T1564.001 Hidden Files and Directories T1070.006 Timestomp T1070 Indicator Removal T1057 Process Discovery T1546.013 PowerShell Profile T1083 File and Directory Discovery T1204.001 Malicious Link T1078 Valid Accounts T1204.004 Malicious Copy and Paste T1583.008 Malvertising T1497.003 Time Based Checks T1003 OS Credential Dumping T1113 Screen Capture T1056.001 Keylogging T1074 Data Staged T1030 Data Transfer Size Limits T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol T1566.002 Spearphishing Link T1020 Automated Exfiltration T1518 Software Discovery T1528 Steal Application Access Token T1567 Exfiltration Over Web Service T1649 Steal or Forge Authentication Certificates T1583 Acquire Infrastructure T1219 Remote Access Tools T1098.004 SSH Authorized Keys T1552 Unsecured Credentials T1216.002 SyncAppvPublishingServer T1053 Scheduled Task/Job T1598 Phishing for Information T1059 Command and Scripting Interpreter T1583.001 Domains T1053.005 Scheduled Task T1548 Abuse Elevation Control Mechanism