A new MacSync malware-as-a-service campaign targets macOS cryptocurrency users and developers with trojanized DMG applications, binary loaders, and droppers. Originally advertised as Mac.c in 2025, the stealer has progressed from AppleScript payloads to Swift and Objective-C binaries and now uses Apple iCloud Calendar and file-hosting infrastructure to retrieve subsequent payloads.
MacSync collects browser and cryptocurrency-wallet data, credentials, Keychain-related material, Telegram data, cloud and developer configuration files, system details, and shell histories. It persists through LaunchAgents, modified ZSH settings, global Git hooks, Login Items, and restoration scripts while suppressing user notifications; its backdoor can receive C2 tasks to install browser extensions, replace Ledger wallet software, repeat collection, and potentially intercept browser traffic.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
Researchers first observed an updated MacSync campaign using malicious DMG application bundles, binary loaders and droppers, and iCloud Calendar and file-hosting infrastructure to deliver later-stage payloads. The campaign included Toria cryptocurrency-wallet impersonation and deployed an infostealer and Objective-C backdoor with extensive persistence and data-theft capabilities.
The macOS information and cryptocurrency stealer was advertised under the name Mac.c on dark-web forums before its developers renamed it MacSync.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 53 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcesecurelist.ru
Open sourcesecurelist.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.