MacSync under the microscope: new delivery methods and a new payload
2026-09-25T20:51:46Z•86ddb7d79c4085cf4d5f525ef74e4aa23fee550acc18012f7bee4a126bba3a72
APTActive DirectoryActive Directory exploitationAfricaC2 concealmentElementFinTechGhostContainerGitHubGroup PolicyLiving off the landMQTTMatrixMiddle EastNode.js malware','JavaScript malware'RDPSolanaaviationbackdoorbinary-less attackcryptocurrency theftdeveloper targetingmacOS stealerransomwaretorrent malware
What happened
Kaspersky Securelist reports from August–September 2026 covering macOS infostealing, ransomware abuse of Active Directory Group Policy, torrent-delivered malware using Solana for C2 concealment, APT campaigns, MQTT and Matrix-based backdoors, new JavaScript/Node.js malware, ValleyRAT distribution, industrial-control threats, vulnerability trends including AI frameworks, and Android proxy-botnet malware targeting automotive head units.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- 86ddb7d79c4085cf4d5f525ef74e4aa23fee550acc18012f7bee4a126bba3a72
- Enrichment time
- 2026-09-25T20:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.