Kaspersky has uncovered a new MacSync variant that uses an infostealer and a persistent backdoor to steal credentials, crypto wallet data, files, and developer-related information from Mac users. The campaign spreads through a fake crypto wallet app called Toria and uses advanced infection chains, disguised prompts, and a backdoor posing as Finder to target developers and crypto enthusiasts. #MacSync #Kaspersky #Toria #Finder #Ledger #PAM #Keychain
Keypoints
- MacSync has evolved into a more advanced Mac infostealer and backdoor threat.
- The malware was distributed through the fake crypto wallet app Toria.
- Attackers used multi-stage droppers, loaders, and even a public iCloud calendar in the infection chain.
- The stealer harvests browser data, Keychain data, crypto wallet files, Telegram data, and developer configs.
- The backdoor disguises itself as Finder and can reinstall itself through persistence mechanisms.
Read More: https://www.helpnetsecurity.com/2026/09/25/macsync-info-stealing-malware-for-macos/