MacSync is a relatively young, rapidly evolving family of crypto/info stealers. First advertised on the dark web in 2025 as Mac.c, the stealer was later renamed to MacSync by its creators. The initial versions were implemented as AppleScripts and closely resembled the AMOS stealer family, but over time, MacSync developed distinctive features of its own, including a backdoor module.
MacSync under the microscope: new delivery methods and a new payload
About this summary. This is a short, independently written summary of an article first published by Kaspersky Securelist. Cyber Security News did not report or verify the underlying story. Read the original: https://securelist.com/macsync-new-version/121383/

Source attribution: headline and facts are from Kaspersky Securelist (securelist.com). Summary method: excerpt of the source description. See our source attribution policy.





