Malware · 7h ago
Kaspersky says a new MacSync macOS stealer variant, first spotted in the wild in September 2026, replaces the family’s earlier AppleScript-style droppers with compiled Objective-C and Swift modules. The same report says the infection chain also uses iCloud at one stage to pass the next payload.
That shift matters because the malware no longer looks like an obvious script launch or single-file dropper. Instead, it moves through normal-looking app and cloud behavior, which makes script-focused detection and simple file-hash checks easier to miss while the stealer and its backdoor chain run.
The result is a cleaner fit for the same ecosystem that already tolerates unsigned DMGs, cracked apps, and fake wallet software. For macOS teams, the exposure is not just one infected host but developer machines and crypto users that can hand the malware a more believable place to live.
2 sources covering this story
MacSync malware uses public iCloud calendars to deliver new payloads
A new variant of the MacSync malware targeting macOS systems now uses public iCloud calendar events to deliver new native payloads.
A new version of the MacSync macOS stealer targets crypto enthusiasts and developers
We look at a new version of the MacSync macOS stealer with a backdoor module that targets crypto enthusiasts and developers.
Part of the PlainSec briefing for 2026-09-24