• Trending
  • Comments
  • Latest
Ian Issa explains how HashNet turned Zcash's $50-to-$600 rally into Bitcoin without holding a coin

Ian Issa explains how HashNet turned Zcash’s $50-to-$600 rally into Bitcoin without holding a coin

07/18/2026 - Updated on 07/19/2026
Leaked Chainalysis Video Raises Concerns Over Monero Traceable Transaction Claim

Chainalysis sues US government over $94.66 million ICE contract awarded to TRM Labs

08/18/2026
The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

04/18/2026 - Updated on 05/25/2026
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1
crypto-linked forex scheme

CFTC sues Cash FX over alleged $950 million crypto forex Ponzi scheme

09/26/2026
Crypto malware

MacSync malware replaces Ledger wallets with malicious clones on Macs

09/26/2026
EJPY stablecoin

Toshiba and 25 other firms join Japan’s six-month EJPY stablecoin trial on Japan Open Chain

09/26/2026
  • Trending
  • Comments
  • Latest
Ian Issa explains how HashNet turned Zcash's $50-to-$600 rally into Bitcoin without holding a coin

Ian Issa explains how HashNet turned Zcash’s $50-to-$600 rally into Bitcoin without holding a coin

07/18/2026 - Updated on 07/19/2026
Leaked Chainalysis Video Raises Concerns Over Monero Traceable Transaction Claim

Chainalysis sues US government over $94.66 million ICE contract awarded to TRM Labs

08/18/2026
The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

04/18/2026 - Updated on 05/25/2026
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1
crypto-linked forex scheme

CFTC sues Cash FX over alleged $950 million crypto forex Ponzi scheme

09/26/2026
Crypto malware

MacSync malware replaces Ledger wallets with malicious clones on Macs

09/26/2026
EJPY stablecoin

Toshiba and 25 other firms join Japan’s six-month EJPY stablecoin trial on Japan Open Chain

09/26/2026
Saturday, September 26, 2026
  • Login
The Bit Gazette
  • Home
  • Crypto News
  • Expert Analysis
  • Finance
  • Tech
  • Sponsored
  • Press Release
  • Opinion
No Result
View All Result
The Bit Gazette
No Result
View All Result
Home Crypto News

MacSync malware replaces Ledger wallets with malicious clones on Macs

The latest MacSync malware campaign is using malicious macOS applications to target cryptocurrency users and developers, with researchers at Kaspersky’s Securelist identifying a more complex delivery chain in September 2026.

by Moses Edozie
1 hour ago
in Crypto News
Reading Time: 4 mins read
0
Crypto malware

Crypto malware

Share on FacebookShare on Twitter

A new MacSync malware campaign is using fake macOS apps, a bogus crypto wallet called Toria, and hijacked iCloud calendar invites to steal wallet data, passwords, and developer credentials from Mac users, and in some cases swap out victims’ real Ledger hardware wallets for malicious clones, according to a Kaspersky-linked Securelist analysis shared with Cyber Security News.

MacSync malware shifts to malicious macOS applications

The new MacSync malware activity begins with a malicious DMG file containing an application bundle. According to the Securelist analysis cited in the supplied report, attackers can vary the infection process between campaigns.

One route executes a compiled JXA script directly in memory. Another uses a chain of loaders and droppers before downloading the final malicious components. Both approaches ultimately deliver an information stealer and a backdoor.

Kaspersky said the shift from script-based delivery to compiled components gives the malware greater flexibility and additional ways to conceal its activity across both Apple Silicon and Intel-based Macs.

“The change makes MacSync more flexible while giving attackers more ways to hide activity on both Apple Silicon and Intel Macs.” — Kaspersky, in a report shared with Cyber Security News

The infection chain can also abuse legitimate Apple services. In one observed route, a loader retrieves a public iCloud calendar and uses information hidden in an event description to obtain further commands.

Those commands download an archive containing another application, remove security markings, apply an ad-hoc signature and execute the program. The technique effectively turns a routine calendar-sharing feature into another stage of the malware delivery process.

The MacSync malware then decrypts later-stage payloads containing an information stealer and backdoor. Temporary files and lock files help control execution, while completed components can remove logs and other traces.

MacSync malware targets passwords, wallets and developer credentials

The malware’s theft capabilities extend beyond cryptocurrency wallets. Its Swift-based stealer can display an administrator-password request designed to resemble the legitimate application being imitated.

After the victim enters the password, the malware can present a fake warning suggesting that the application is damaged. Researchers said the stealer verifies the supplied password through macOS authentication interfaces rather than relying on the older command-line approach.

The MacSync malware can collect browser history, cookies, stored login information, wallet-extension data, Keychain files, Telegram information and device details.

Its targeting also extends into developer environments. The malware searches configuration files and histories associated with SSH, ZSH, AWS, Kubernetes and Git. Such information can contain credentials or access details for cloud infrastructure, source-code repositories and other development resources.

The backdoor communicates through HTTP and can receive commands, upload files and deploy a browser extension. Researchers also found functionality capable of replacing an installed Ledger wallet with a malicious version.

A live-browser capability may allow attackers to intercept browser traffic, although researchers were unable to establish the precise purpose of the associated helper. The command scripts themselves were not available to the researchers.

MacSync malware uses multiple persistence techniques

The campaign also employs techniques intended to keep access active after the initial malicious application has been removed.

The malware can disguise itself as Finder and establish persistence through a LaunchAgent, ZSH startup settings and global Git hooks. Its repair routine can restore files and suppress startup notifications, meaning removal of the initial application may not necessarily eliminate the wider infection.

Cyber security

The MacSync malware also checks for virtual machines and blocks debuggers, measures that can complicate analysis and investigation on infected systems.

Researchers identified persistence mechanisms including the com.apple.finder.agent LaunchAgent, modified pre-commit and post-checkout Git hooks, and changes to the .ZSHRC shell startup file.

The campaign’s infrastructure includes several malicious domains and URLs, along with identifiable file artifacts, hashes, command-and-control endpoints and temporary paths. The supplied report lists indicators including the fake Toria wallet website, malicious DMG locations, encrypted payloads, backdoor infrastructure and HTTP access tokens.

The indicators are intentionally defanged in the report to prevent accidental resolution or interaction.

MacSync malware raises risks for crypto and development users

The combination of credential theft, cryptocurrency targeting and access to developer environments broadens the potential consequences of a successful infection. Stolen browser sessions, wallet information, cloud keys, SSH settings and source-control credentials could expose personal accounts and provide access to resources beyond the original Mac.

The MacSync malware campaign also demonstrates how attackers can combine malicious applications with legitimate services and macOS features to complicate detection.

Researchers recommend that users obtain software only from verified developer websites and avoid cracked or unofficial applications. Users should also avoid bypassing macOS security warnings, pasting unverified commands into Terminal or approving unexpected password prompts.

Organizations using Macs should investigate unfamiliar startup items, modified Git hooks and suspicious outbound file transfers. The report also recommends reviewing persistence mechanisms when investigating suspected infections rather than focusing only on the initial malicious application.

If a device is believed to be compromised, users should isolate the Mac, revoke active sessions and replace credentials from a trusted device. Persistence locations should be reviewed before the system is returned to normal network access.

The researchers did not provide a victim count, so the extent of the campaign remains unknown. However, the observed delivery methods show that the MacSync malware has expanded beyond its earlier reliance on straightforward script-based execution, combining application masquerading, credential theft, persistence and remote access in a more varied infection chain.

Source: Cyber Security News

Tags: AppleAtkinsblockchaincoinbasecompliancecryptoCryptocurrencycryptojackingcyber threatcybersecuritydata theftdevelopersDigitalAssetsenforcementGenslerInfostealerKrakenlitigationMac securitymacOSMacSyncmalwaremalware attackmarketspasswordsPeircepolicyRegulationripplesecsecuritiestrumpUyedawallets
Share197Tweet123
Moses Edozie

Moses Edozie

Moses Edozie is a writer and storyteller with a deep interest in cryptocurrency, blockchain innovation, and Web3 culture. Passionate about DeFi, NFTs, and the societal impact of decentralized systems, he creates clear, engaging narratives that connect complex technologies to everyday life.

  • Trending
  • Comments
  • Latest
Ian Issa explains how HashNet turned Zcash's $50-to-$600 rally into Bitcoin without holding a coin

Ian Issa explains how HashNet turned Zcash’s $50-to-$600 rally into Bitcoin without holding a coin

07/18/2026 - Updated on 07/19/2026
Leaked Chainalysis Video Raises Concerns Over Monero Traceable Transaction Claim

Chainalysis sues US government over $94.66 million ICE contract awarded to TRM Labs

08/18/2026
The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

04/18/2026 - Updated on 05/25/2026
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1
crypto-linked forex scheme

CFTC sues Cash FX over alleged $950 million crypto forex Ponzi scheme

09/26/2026
Crypto malware

MacSync malware replaces Ledger wallets with malicious clones on Macs

09/26/2026
EJPY stablecoin

Toshiba and 25 other firms join Japan’s six-month EJPY stablecoin trial on Japan Open Chain

09/26/2026
The Bit Gazette

Copyright © 2025 - The Bit Gazette.

Navigate Site

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Follow Us

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Crypto News
  • Expert Analysis
  • Finance
  • Tech
  • Sponsored
  • Press Release
  • Opinion

Copyright © 2025 - The Bit Gazette.