MacSync under the microscope: new delivery methods and a new payload

2026-09-24T20:51:46Z•662501fe32d7e2106fa046d4380da298046f0b6fa4e2829e8f1b77a5dc11cb81
AI-securityAPTActive DirectoryAndroidC2GitHubGroup Policy ObjectsICSJavaScriptMQTTMatrixNode.jsRDPSolanabackdoorexploitsindustrial-control-systemsinfostealermacOSmalwareproxy-botnetransomwarethreat-intelligencetorrent-distributionvulnerabilities

What happened

Kaspersky Securelist RSS entries covering September–August 2026 threat intelligence, including macOS infostealing with a backdoor, ransomware abusing Active Directory Group Policy, torrent-delivered multi-stage malware using Solana for C2 concealment, APT campaigns targeting Russian organizations and Middle Eastern and African sectors, MQTT/Matrix-based backdoors, ValleyRAT distribution, industrial control system threats, vulnerability and exploit trends including AI frameworks, and Android malware building an advertising proxy botnet.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
662501fe32d7e2106fa046d4380da298046f0b6fa4e2829e8f1b77a5dc11cb81
Enrichment time
2026-09-24T20:51:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.