MacSync is a rapidly evolving family of macOS infostealers that has transitioned from simple AppleScript-based droppers to sophisticated binary modules written in Objective-C and Swift. Recent campaigns demonstrate a complex multi-stage infection chain that utilizes novel delivery methods, including malicious iCloud calendar descriptions and DMG images masquerading as legitimate software like the 'Toria' crypto wallet. This evolution marks a significant shift in the malware's technical complexity and delivery infrastructure.
The malware employs advanced persistence mechanisms, such as modifying ZSH configuration files and Git hooks, while utilizing the PAM API for credential harvesting—a relatively new technique in macOS threats. By targeting developers and cryptocurrency users, MacSync exfiltrates sensitive data including browser cookies, keychain files, and cloud configuration secrets. The use of legitimate Apple infrastructure for payload delivery highlights the increasing sophistication of actors targeting the macOS ecosystem.
Top comments (0)