MacSync under the microscope: new delivery methods and a new payload

2026-09-25T08:51:45Z•a92377971c39cbbbcac508130bb34f979b541a7ef2ffc724745c6827b25b9434
APTActive DirectoryAndroid malwareC2 concealmentGitHubGroup Policy ObjectsJavaScript malwareMQTTMatrixNode.js malwareRDP exploitationSolanaadware masqueradingbackdoorbinaryless attackcryptocurrency targetingdeveloper targetingindustrial control systemsmacOS stealerproxy botnetransomwaretorrent malwarevulnerability intelligence

What happened

Kaspersky Securelist RSS entries describe multiple September 2026 threat campaigns, including the MacSync macOS stealer with a backdoor targeting cryptocurrency users and developers; PAYLOAD ransomware abusing Active Directory Group Policy Objects for binary-less, encryptionless operations; MovieReaper distributed through compromised movie torrents with Solana-based C2 concealment; NightEagle targeting Russian organizations using GhostContainer, GitHub-hosted tools, Active Directory and RDP exploitation; Toy Ghouls backdoors using MQTT and Matrix messaging for command and control; Mirage Kitтe

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
a92377971c39cbbbcac508130bb34f979b541a7ef2ffc724745c6827b25b9434
Enrichment time
2026-09-25T08:51:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.