Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

MacSync Malware Evolves: Binary Droppers, iCloud Delivery, and New Objective‑C/Swift Payloads Target macOS Users

Kaspersky reports that the MacSync macOS infostealer has upgraded to compiled Objective‑C/Swift droppers delivered via malicious DMG files and iCloud. The shift expands the attack surface for macOS endpoints and highlights the need for continuous vendor‑risk monitoring and endpoint telemetry.

LiveThreat™ Intelligence · 📅 September 25, 2026· 📰 securelist.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
4 sector(s)
✅
Actions
4 recommended
📰
Source
securelist.com

MacSync Malware Evolves: Binary Droppers, iCloud Delivery, and New Objective‑C/Swift Payloads Target macOS Users

What Happened – Kaspersky’s SecureList reports that the MacSync infostealer family has shifted from script‑based droppers to compiled binary droppers written in Objective‑C and Swift. The latest campaign (first seen Sep 2026) delivers the first‑stage payload via malicious DMG images and uses iCloud as a secondary delivery channel, allowing the backdoor module to reach victims without writing intermediate files to disk.

Why It Matters for Trust & Control Assurance

  • Continuous control‑assurance programs must surface and log atypical macOS execution paths (e.g., unsigned DMG, in‑memory script decoding) before they succeed.
  • Evidence of third‑party malware‑as‑a‑service (MaaS) activity underscores the need for ongoing vendor risk monitoring and proof of due‑diligence on the software supply chain.
  • Defensible audit trails that capture endpoint telemetry (file creation in /tmp, iCloud traffic anomalies) provide the documentation required for regulatory readiness.

Who Is Affected – Enterprises and individuals using macOS devices across technology, finance, creative, and education sectors; any organization that permits installation of third‑party applications from untrusted sources.

Recommended Actions

  • Enforce strict code‑signing and notarization policies; block execution of unsigned DMG files.
  • Deploy endpoint detection and response (EDR) that records file creation in /tmp and monitors iCloud API usage.
  • Incorporate MacSync indicators of compromise into threat‑intel feeds and automate alerting.
  • Review third‑party software procurement processes to ensure continuous vetting of “free” or “cracked” applications.

Source: SecureList – MacSync new version

Technical Notes

  • Infection chain: Malicious DMG → compiled JXA script (in‑memory decode) → Objective‑C/Swift backdoor module.
  • Delivery vectors: Social‑engineering (fake crypto‑wallet app), iCloud file sharing, and disguised “free” macOS apps.
  • Payloads: Infostealer modules (credential harvesting) and a persistent backdoor.
  • Indicators: HEUR:Trojan.OSX.MacSync., HEUR:Trojan‑PSW.OSX.MacSync., HEUR:Trojan‑Dropper.OSX.MacSync., HEUR:Trojan‑Downloader.OSX.MacSync..

Source: SecureList – Technical details

📰 Original Source
https://securelist.com/macsync-new-version/121383/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

Point-in-time vendor reviews miss incidents like this.

Verisq AI Trust Operations replaces the annual questionnaire with continuous third-party monitoring — so vendor exposure becomes audit evidence, not a once-a-year guess.

See how Verisq AI Trust Operations works →