MacSync Malware Evolves: Binary Droppers, iCloud Delivery, and New Objective‑C/Swift Payloads Target macOS Users
What Happened – Kaspersky’s SecureList reports that the MacSync infostealer family has shifted from script‑based droppers to compiled binary droppers written in Objective‑C and Swift. The latest campaign (first seen Sep 2026) delivers the first‑stage payload via malicious DMG images and uses iCloud as a secondary delivery channel, allowing the backdoor module to reach victims without writing intermediate files to disk.
Why It Matters for Trust & Control Assurance
- Continuous control‑assurance programs must surface and log atypical macOS execution paths (e.g., unsigned DMG, in‑memory script decoding) before they succeed.
- Evidence of third‑party malware‑as‑a‑service (MaaS) activity underscores the need for ongoing vendor risk monitoring and proof of due‑diligence on the software supply chain.
- Defensible audit trails that capture endpoint telemetry (file creation in /tmp, iCloud traffic anomalies) provide the documentation required for regulatory readiness.
Who Is Affected – Enterprises and individuals using macOS devices across technology, finance, creative, and education sectors; any organization that permits installation of third‑party applications from untrusted sources.
Recommended Actions
- Enforce strict code‑signing and notarization policies; block execution of unsigned DMG files.
- Deploy endpoint detection and response (EDR) that records file creation in /tmp and monitors iCloud API usage.
- Incorporate MacSync indicators of compromise into threat‑intel feeds and automate alerting.
- Review third‑party software procurement processes to ensure continuous vetting of “free” or “cracked” applications.
Source: SecureList – MacSync new version
Technical Notes
- Infection chain: Malicious DMG → compiled JXA script (in‑memory decode) → Objective‑C/Swift backdoor module.
- Delivery vectors: Social‑engineering (fake crypto‑wallet app), iCloud file sharing, and disguised “free” macOS apps.
- Payloads: Infostealer modules (credential harvesting) and a persistent backdoor.
- Indicators: HEUR:Trojan.OSX.MacSync., HEUR:Trojan‑PSW.OSX.MacSync., HEUR:Trojan‑Dropper.OSX.MacSync., HEUR:Trojan‑Downloader.OSX.MacSync..
Source: SecureList – Technical details