Malware & Tooling · Credential Theft

MacSync Swaps Scripts for Native macOS Binaries

Kaspersky says a new MacSync macOS stealer variant, first spotted in the wild in September 2026, replaces the family’s earlier AppleScript-style droppers with compiled Objective-C and Swift modules. The same report says the infection chain also uses iCloud at one stage to pass the next payload.

That shift matters because the malware no longer looks like an obvious script launch or single-file dropper. Instead, it moves through normal-looking app and cloud behavior, which makes script-focused detection and simple file-hash checks easier to miss while the stealer and its backdoor chain run.

The result is a cleaner fit for the same ecosystem that already tolerates unsigned DMGs, cracked apps, and fake wallet software. For macOS teams, the exposure is not just one infected host but developer machines and crypto users that can hand the malware a more believable place to live.

2 sources · 9h ago

Timeline

Sources

Part of the PlainSec briefing for 2026-09-24

Every edition of this story: MacSync Swaps Scripts for Native macOS Binaries