Wire Observer.
Technology

MacSync malware evolves, targeting macOS users of crypto and developer tools

MacSync malware evolves, targeting macOS users of crypto and developer tools

A newly observed variant of the MacSync information stealer is shifting its tactics, deploying a more elaborate infection chain aimed at macOS users who handle cryptocurrency and software development tools.

Earlier iterations of MacSync primarily relied on a single line of code pasted into the Terminal, a method that often caught users off guard but left a relatively simple forensic trail. The latest campaigns, however, begin with seemingly innocuous disk‑image (DMG) files that, when opened, silently install additional payloads before presenting a legitimate‑looking application.

Security researchers say the updated delivery mechanism is designed to blend in with the workflows of developers and crypto enthusiasts. The malicious DMG files are often disguised as popular utilities—such as blockchain wallets, code editors, or package managers—leveraging the trust users place in these tools. Once the image is mounted, a hidden installer drops a secondary component that modifies existing applications, turning them into conduits for credential harvesting and cryptocurrency mining.

Technical analysis reveals that the new MacSync strain employs a multi‑stage loader written in Swift, which dynamically fetches encrypted modules from command‑and‑control servers. These modules include keyloggers, clipboard monitors, and code that injects malicious scripts into development environments, allowing attackers to capture API keys, private keys, and other sensitive data. In addition, the malware can silently mine cryptocurrencies, using the victim's hardware resources without obvious performance degradation.

The shift toward a more sophisticated delivery chain reflects a broader trend in macOS‑focused threats. While macOS has historically been perceived as a lower‑risk platform compared to Windows, the growing popularity of the operating system among developers and the increasing value of digital assets have made it a more attractive target for financially motivated cybercrime.

Experts advise users to verify the source of any DMG file before opening it, especially when the file claims to be a crypto wallet or a development tool. Enabling Gatekeeper's stricter settings, keeping the operating system and all applications up to date, and employing reputable endpoint protection can reduce the risk of infection. For organizations, implementing application whitelisting and monitoring for unusual process activity can help detect the stealthy behaviors associated with MacSync.

Researchers continue to monitor the malware's evolution, noting that its modular architecture allows rapid updates to bypass emerging defenses. As the line between legitimate developer utilities and malicious code blurs, vigilance remains the most effective safeguard against this emerging macOS threat.

Kabir Rao — Security desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related