MacSync under the microscope: new delivery methods and a new payload

2026-09-25T20:51:46Z•86ddb7d79c4085cf4d5f525ef74e4aa23fee550acc18012f7bee4a126bba3a72
APTActive DirectoryActive Directory exploitationAfricaC2 concealmentElementFinTechGhostContainerGitHubGroup PolicyLiving off the landMQTTMatrixMiddle EastNode.js malware','JavaScript malware'RDPSolanaaviationbackdoorbinary-less attackcryptocurrency theftdeveloper targetingmacOS stealerransomwaretorrent malware

What happened

Kaspersky Securelist reports from August–September 2026 covering macOS infostealing, ransomware abuse of Active Directory Group Policy, torrent-delivered malware using Solana for C2 concealment, APT campaigns, MQTT and Matrix-based backdoors, new JavaScript/Node.js malware, ValleyRAT distribution, industrial-control threats, vulnerability trends including AI frameworks, and Android proxy-botnet malware targeting automotive head units.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
86ddb7d79c4085cf4d5f525ef74e4aa23fee550acc18012f7bee4a126bba3a72
Enrichment time
2026-09-25T20:51:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.