MacSync under the microscope: new delivery methods and a new payload
2026-09-25T08:51:45Z•a92377971c39cbbbcac508130bb34f979b541a7ef2ffc724745c6827b25b9434
APTActive DirectoryAndroid malwareC2 concealmentGitHubGroup Policy ObjectsJavaScript malwareMQTTMatrixNode.js malwareRDP exploitationSolanaadware masqueradingbackdoorbinaryless attackcryptocurrency targetingdeveloper targetingindustrial control systemsmacOS stealerproxy botnetransomwaretorrent malwarevulnerability intelligence
What happened
Kaspersky Securelist RSS entries describe multiple September 2026 threat campaigns, including the MacSync macOS stealer with a backdoor targeting cryptocurrency users and developers; PAYLOAD ransomware abusing Active Directory Group Policy Objects for binary-less, encryptionless operations; MovieReaper distributed through compromised movie torrents with Solana-based C2 concealment; NightEagle targeting Russian organizations using GhostContainer, GitHub-hosted tools, Active Directory and RDP exploitation; Toy Ghouls backdoors using MQTT and Matrix messaging for command and control; Mirage Kitтe
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- a92377971c39cbbbcac508130bb34f979b541a7ef2ffc724745c6827b25b9434
- Enrichment time
- 2026-09-25T08:51:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.