← NEWS & INSIGHTS

NEWS / RESEARCH & ANALYSIS

MacSync evolves: native macOS modules change the evidence trail

Kaspersky documents a September MacSync infection chain with Objective-C and Swift components, a backdoor module and delivery through disk images.

Source published 2026-09-24Malware analysisResearch briefing
Original publication preview: MacSync evolves: native macOS modules change the evidence trail
Kaspersky / Securelist ↗

Findings and evidence

Kaspersky documents a September MacSync infection chain with Objective-C and Swift components, a backdoor module and delivery through disk images. Its analysis compares the newer binaries with earlier script-based variants and describes an intermediate use of iCloud.

Why it matters

For a macOS investigation, correlate the downloaded application, quarantine metadata, process history and network records. A change of implementation language can invalidate assumptions based on an older sample; maintain a versioned account of the evidence.

Scope and limits

This is a vendor analysis of observed variants. The presence of a disk image or an iCloud connection alone does not establish compromise.

Primary source

Kaspersky / Securelist: original publication. Source published 2026-09-24. Brief prepared by websec.gr on 26 September 2026. This is an editorial research summary, not a claim of independent replication.

Search the lab

NEWS / FORENSICS / FIELD GUIDES ESC