
Findings and evidence
Kaspersky documents a September MacSync infection chain with Objective-C and Swift components, a backdoor module and delivery through disk images. Its analysis compares the newer binaries with earlier script-based variants and describes an intermediate use of iCloud.
Why it matters
For a macOS investigation, correlate the downloaded application, quarantine metadata, process history and network records. A change of implementation language can invalidate assumptions based on an older sample; maintain a versioned account of the evidence.
Scope and limits
This is a vendor analysis of observed variants. The presence of a disk image or an iCloud connection alone does not establish compromise.
Primary source
Kaspersky / Securelist: original publication. Source published 2026-09-24. Brief prepared by websec.gr on 26 September 2026. This is an editorial research summary, not a claim of independent replication.