MacSync Stealer Poses as Apps, Uses iCloud Drops

Securelist · High sophistication
Last updated September 24, 2026

Kaspersky reports a real-world MacSync infostealer campaign seen in September 2026 that tricks users into installing fake or cracked macOS apps. The attack uses staged downloads (including iCloud Calendar content) and then prompts the user for an administrator password using realistic-looking pop-ups that mimic the impersonated app and a macOS warning.

Key findings

  • MacSync is a macOS info/crypto stealer sold as malware-as-a-service (MaaS) and observed in the wild in September 2026.
  • Attackers distributed it by disguising it as "free or cracked versions of popular applications" and "under the guise of new software," including a fake crypto wallet named "Toria," promoted on X and Telegram.
  • The campaign used malicious DMG images and multi-stage droppers/loaders, including delivery of commands hidden inside an iCloud Calendar file (abusing the calendar DESCRIPTION field).
  • The infostealer prompts users for an "administrator password" and shows a follow-up fake macOS-style warning claiming the app is corrupted and offering to move it to the trash.
  • Persistence mechanisms included a LaunchAgent and injecting commands into shell startup files (e.g., .zshrc) and Git hooks.

Who’s being targeted

  • Commonly targeted roles: All employees (macOS users), Finance teams, IT/helpdesk, Executives and admins with local admin rights.
  • Affected industries: Cross-industry (macOS users), Cryptocurrency users.
  • Attack channels: website, telegram, email.
  • Impersonated: A crypto wallet app brand ("Toria"), A legitimate macOS application (the pop-up is adapted to match the impersonated app).

Awareness takeaways

  • Treat “free/cracked” software and brand-new apps promoted on social media/Telegram as high risk; require employees to use approved software sources.
  • Train users to stop and verify when a newly installed app immediately asks for an administrator password.
  • Teach users that “app is corrupted, move to trash” pop-ups can be fake and may appear after credential theft; report it rather than clicking through.
  • Include cloud-service abuse in awareness messaging (attackers can use legitimate services like iCloud as part of delivery).

Red flags to watch for

  • Brand-new or unfamiliar app name promoted via social media/Telegram
  • Software not found in official vendor channels (e.g., App Store / known publisher)
  • Installer delivered as a DMG from a promotional page rather than a trusted source
  • Unexpected request for an administrator password immediately after launching a newly installed app
  • Password prompt appears outside normal corporate software installation flow
  • Follow-on “corrupted application” warning right after providing the password
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Imagine this: a shiny new crypto wallet called “Toria” pops up on X and Telegram, promising a free macOS app. You download the Toria DMG, open it, and the “wallet” instantly asks for your Mac administrator password, then shows a fake macOS alert saying the app is corrupted and can be moved to the trash. That’s MacSync infostealer doing its job. Behind that, MacSync is a malware‑as‑a‑service infostealer. It came from a malicious DMG, pulls extra commands from things like an iCloud Calendar file, and then digs in using LaunchAgents and edits to files like .zshrc and Git hooks. If any new Mac app, especially a “free” or social‑media‑only one, immediately asks for your admin password or says it’s corrupted, stop. Close it and report it to IT Security right away.

Categories

Similar attacks

Invoice Phish Leads to Resilient ValleyRAT

Invoice Phish Leads to Resilient ValleyRAT

A Japanese industrial manufacturer was targeted by the SilverFox group using an invoice-themed phishing email that kicked off a multi-stage malware chain. The campaign abused legitimate software and cloud services to load a malicious DLL, disable security tools, and establish remote access with…

July 31, 2026
Fake Recruiters Push “Coding Tests” as RAT Traps

Fake Recruiters Push “Coding Tests” as RAT Traps

Researchers say the Iran-linked group Nimbus Manticore posed as recruiters on LinkedIn and job platforms to send developers “technical challenge” ZIP files that secretly installed cross-platform remote access trojans. The lures used urgency (short test windows) and realistic developer workflows…

September 1, 2026
Fake GitHub Lure Tricks macOS Users Into Stealer

Fake GitHub Lure Tricks macOS Users Into Stealer

Researchers described AmnesiaStealer, a macOS info-stealer spread through a counterfeit “Download for macOS” page that tricks users into pasting a command into Terminal. The malware steals passwords and browser session data, and can even give an attacker live, hidden control of the victim’s browser…

August 17, 2026
Fake LastPass GitHub Drops Rapuncel Stealer

Fake LastPass GitHub Drops Rapuncel Stealer

Attackers impersonated LastPass on GitHub and tricked people searching for the “LastPass Authenticator download” into installing a fake installer. The infection chain used a Microsoft-signed driver to disable many security tools, then deployed an infostealer that stole passwords, crypto wallets,…

September 23, 2026
ClickFix Lures Spread ChainScript RAT

ClickFix Lures Spread ChainScript RAT

Researchers describe real-world “ClickFix” social-engineering lures that trick people into installing malware by downloading fake apps (like Spotify/Zoom/Teams) or copying commands into Terminal. One campaign abused a compromised, verified HBO Max Reddit account to run malicious ads, while another…

September 21, 2026
Prompt Injection Steals Agent Vault Secrets

Prompt Injection Steals Agent Vault Secrets

Unit 42 showed that default AWS AgentCore Harness settings can let an attacker use prompt injection to trick an AI agent into running shell commands and exposing plaintext credentials from AgentCore Identity at runtime. In their demo, a malicious support ticket embedded instructions (via hidden…

September 18, 2026