MacSync is a macOS stealer sold as malware-as-a-service. On September 24, 2026, Kaspersky published an analysis of a new version with two parts: a stealer that takes browser data, wallet data, Telegram data, your Mac password and your keychain file, and a backdoor that disguises itself as Finder. One of the backdoor’s commands, deploy_ledger, replaces the installed Ledger wallet app with a version from the attackers’ server.

Here is what the infection looks like from your side of the screen, what the much-discussed iCloud calendar actually does, and how to check whether you still have the real Ledger app.

How it arrives

The new chain starts with a disk image. Kaspersky found it posing as a wallet app called Toria, which doesn’t exist; the attackers built a website for it and promoted it on X and Telegram. MacSync has also spread as cracked versions of popular apps, and earlier versions used fake installation guides that told people to paste a command into Terminal.

When you open the app, it strips the quarantine flag that macOS uses to trigger Gatekeeper checks, then quietly downloads the next stages.

What “iCloud Calendar” means here

This detail has been widely reported as the malware using iCloud Calendar for command and control. It’s more specific than that, and the difference matters.

  • In at least one sample, the first loader fetched a public calendar the attackers published on iCloud. The next set of shell commands was hidden in an event’s description field, and the loader fed the whole calendar file to the shell.
  • Those commands then downloaded the next stage, also from iCloud, and ran it with an ad-hoc signature.
  • The actual command-and-control server, which gives the backdoor its orders and receives stolen data, is on attacker-controlled domains, not iCloud.

What it means for you: your own iCloud account isn’t involved or compromised, and you don’t need an iCloud account for this to work. It also means network filters that trust Apple’s domains won’t catch the early stages, because the traffic goes to icloud.com. So don’t rely on your network to protect you; rely on not running the app in the first place.

What you see on screen

  1. A password prompt styled to match the app you think you’re installing. It asks for your Mac administrator password.
  2. After you enter it, a message that looks like a system notice, saying the app is damaged and offering to move it to the Trash.
  3. Nothing else. The stealer has already packed up your data, and the backdoor starts in the background.

That “damaged app” message is the tell. If you entered your password into a new app and then saw it, assume the Mac is infected.

How the fake Ledger app works

The backdoor can replace your Ledger app on command. Earlier MacSync versions did the same to Ledger Live and Trezor Suite by swapping the file inside the app that contains its interface code. Because Ledger’s desktop app is built on Electron, the attackers can change what you see without touching the rest.

The result looks like the app you know. At some point, it tells you something is wrong and asks for your 24-word recovery phrase to fix it. Once you type it, the attackers can rebuild your wallet on their own device and empty it. Your hardware wallet can’t protect a recovery phrase you type into a computer.

Check you still have the real Ledger app

The modified app can’t carry Ledger’s signature, because changing the contents breaks it. Attackers re-sign it with an ad-hoc signature, which names no developer. Check in Terminal, using Ledger Wallet.app or Ledger Live.app, whichever you have:

codesign -dvv "/Applications/Ledger Wallet.app" 2>&1 | grep -E "Authority|TeamIdentifier|Signature"
codesign --verify --deep --strict --verbose=2 "/Applications/Ledger Wallet.app"
spctl -a -vv "/Applications/Ledger Wallet.app"
  • Real: an Authority=Developer ID Application: line naming Ledger, a TeamIdentifier, “valid on disk” and “satisfies its Designated Requirement”, and accepted with source=Notarized Developer ID.
  • Tampered: Signature=adhoc, TeamIdentifier=not set, a sealed resource error, or rejected.

Run the same checks on "/Applications/Trezor Suite.app" if you use Trezor. If in doubt, delete the app and download it again only from Ledger’s or Trezor’s own website, typed into the address bar rather than found through search ads.

Check for the backdoor

These locations come from Kaspersky’s analysis. Finding any of them is a strong sign of infection:

ls ~/Library/LaunchAgents | grep -i "com.apple.finder.agent"
ls -la ~/Library/Application\ Support/System 2>/dev/null
grep -n "repair-run" ~/.zshrc
ls -la ~/Library/Logs/.sysnotif-agent.log 2>/dev/null
git config --global core.hooksPath
  • Apple doesn’t install a LaunchAgent called com.apple.finder.agent in your user folder, and ~/Library/Application Support/System doesn’t exist on a normal Mac.
  • The backdoor also adds itself to your shell startup file and to global Git hooks, and can restore itself if you delete only some of its files.
  • It kills the process that normally warns you when a new background item is added, so the absence of a warning proves nothing.

If you find something

  1. Disconnect the Mac from the internet.
  2. From a different, clean device, move funds from any wallet whose recovery phrase or password was on, typed into, or stored on this Mac, to a new wallet with a new recovery phrase. If you only ever approved transactions on your hardware wallet’s screen and never typed the phrase anywhere, your keys are likely safe, but move funds anyway if you have any doubt.
  3. Change passwords from the clean device, starting with email, your Apple Account and exchanges. Sign out of all sessions, since browser cookies were stolen.
  4. Rotate developer credentials: SSH keys, cloud access keys and tokens. MacSync takes these too.
  5. Erase the Mac and reinstall macOS. Don’t try to clean it by hand; the backdoor is built to reinstall itself. Restore documents, not apps, from a backup made before the infection.

The short version

MacSync arrives as a fake or cracked app, asks for your Mac password, pretends to be damaged, then installs a backdoor disguised as Finder that can swap your Ledger app. The iCloud calendar is a delivery trick, not your account being hacked. Check your Ledger and Trezor apps with codesign and spctl, look for the backdoor’s files, and never type a recovery phrase into any app on a computer.