A new MacSync variant targets Mac users with an infostealer and persistent backdoor designed to steal credentials, crypto wallet data, and files, according to Kaspersky. Researchers found the malware spreading through a crypto wallet app called Toria, which had its own website and was promoted on X and Telegram. MacSync is a family of Mac malware that emerged in 2025 as Mac.c and was later renamed.
MacSync info-stealing malware hides malicious commands in an iCloud calendar
About this summary. This is a short, independently written summary of an article first published by Help Net Security. Cyber Security News did not report or verify the underlying story. Read the original: https://www.helpnetsecurity.com/2026/09/25/macsync-info-stealing-malware-for-macos/

Source attribution: headline and facts are from Help Net Security (helpnetsecurity.com). Summary method: excerpt of the source description. See our source attribution policy.





