MacSync fake Ledger app: how it works and how to check yours
MacSync is a macOS stealer sold as malware-as-a-service. On September 24, 2026, Kaspersky published an analysis of a new version with two parts. One is a stealer that takes browser data, wallet data, Telegram data, your Mac password and your keychain file. The other is a backdoor that disguises itself as Finder. One of the backdoor’s commands, deploy_ledger, replaces the installed Ledger wallet app with a version from the attackers’ server.
This guide covers what an infection looks like from your side of the screen, what the much-discussed iCloud calendar actually does, and how to confirm you still have the real Ledger app.
Who should pay attention
The people most exposed are those who install apps from outside the Mac App Store, download cracked software, or follow guides that say “paste this into Terminal.” That describes plenty of careful users on a bad day.
You don’t need to own crypto to be affected. The stealer goes after browser data, Telegram data, your Mac password and your keychain file whatever else is on the Mac. Owning a Ledger or Trezor adds a second risk, the swapped wallet app. If you use one, run the Ledger check below, and everyone should read the backdoor check.
How it arrives
The new chain starts with a disk image. Kaspersky found it posing as a wallet app called Toria, which doesn’t exist; the attackers built a website for it and promoted it on X and Telegram. MacSync has also spread as cracked versions of popular apps, and earlier versions used fake installation guides that told people to paste a command into Terminal.
When you open the app, it strips the quarantine flag macOS uses to trigger Gatekeeper checks, then quietly downloads the next stages.
Red flags before you open an app
Each of these alone is a reason to stop:
- The app comes from a site you reached through an ad, a post on X or a Telegram message rather than the developer’s own address.
- The software is a cracked copy of a paid app.
- A guide asks you to paste a command into Terminal, or tells you to bypass a macOS warning to get the app to open.
- The first thing a freshly opened app does is ask for your Mac administrator password.
- You can’t find the developer or the app anywhere outside the site that offers it.
What “iCloud Calendar” means here
This detail has been widely reported as the malware using iCloud Calendar for command and control. The reality is narrower, and the difference matters.
- In at least one sample, the first loader fetched a public calendar that the attackers published on iCloud. The next shell commands were hidden in an event’s description field, and the loader fed the entire calendar file to the shell.
- Those commands then downloaded the next stage, also from iCloud, and ran it with an ad-hoc signature.
- The real command-and-control server, which sends the backdoor its orders and receives stolen data, sits on attacker-controlled domains, not on iCloud.
For you this means your own iCloud account isn’t involved or compromised, and the attack works without any iCloud account. It also means network filters that trust Apple’s domains won’t catch the early stages, since the traffic goes to icloud.com. Don’t count on your network to protect you; count on not running the app in the first place.
What you see on screen
- A password prompt styled to match the app you think you’re installing. It asks for your Mac administrator password.
- After you enter it, a message that looks like a system notice, saying the app is damaged and offering to move it to the Trash.
- Nothing else. The stealer has already packed up your data, and the backdoor starts in the background.
That “damaged app” message is the tell. If you typed your password into a new app and then saw it, assume the Mac is infected.
How the fake Ledger app works
The backdoor can replace your Ledger app on command. Earlier MacSync versions did the same to Ledger Live and Trezor Suite by swapping the file inside the app that holds its interface code. Ledger’s desktop app is built on Electron, so the attackers can change what you see without touching the rest of it.
The result looks like the app you know. At some point it tells you something is wrong and asks for your 24-word recovery phrase to fix it. Once you type it, the attackers can rebuild your wallet on their own device and empty it. A hardware wallet can’t protect a recovery phrase you type into a computer — that’s the core of a hot-wallet threat model on a Mac.
Check you still have the real Ledger app
The modified app can’t carry Ledger’s signature, because changing the contents breaks it. Attackers re-sign it with an ad-hoc signature, which names no developer. Check in Terminal, using Ledger Wallet.app or Ledger Live.app, whichever you have. Do it before you open the app:
codesign -dvv "/Applications/Ledger Wallet.app" 2>&1 | grep -E "Authority|TeamIdentifier|Signature"
codesign --verify --deep --strict --verbose=2 "/Applications/Ledger Wallet.app"
spctl -a -vv "/Applications/Ledger Wallet.app"
- Real: an
Authority=Developer ID Application:line naming Ledger, aTeamIdentifier,valid on diskandsatisfies its Designated Requirement, andacceptedwithsource=Notarized Developer ID. - Tampered:
Signature=adhoc,TeamIdentifier=not set, a sealed resource error, orrejected.
Run the same checks on "/Applications/Trezor Suite.app" if you use Trezor. If in doubt, delete the app and download it again only from Ledger’s or Trezor’s own website, typed into the address bar rather than found through search ads.
If a command says the file doesn’t exist, your copy is named differently. List what’s installed:
ls /Applications | grep -i ledger
A clean result tells you about the app’s signature at this moment. It doesn’t prove the Mac is clean; the backdoor check covers the rest.
Check for the backdoor
These locations come from Kaspersky’s analysis. Finding any of them is a strong sign of infection:
ls ~/Library/LaunchAgents | grep -i "com.apple.finder.agent"
ls -la ~/Library/Application\ Support/System 2>/dev/null
grep -n "repair-run" ~/.zshrc
ls -la ~/Library/Logs/.sysnotif-agent.log 2>/dev/null
git config --global core.hooksPath
- Apple doesn’t install a LaunchAgent called
com.apple.finder.agentin your user folder, and~/Library/Application Support/Systemdoesn’t exist on a normal Mac. - The backdoor also adds itself to your shell startup file and to global Git hooks, and it can restore itself if you delete only some of its files.
- It kills the process that normally warns you when a new background item is added, so the absence of a warning proves nothing.
- If the Git command prints a path you never set yourself, look closer.
Empty output isn’t a clean bill of health. These commands only cover the locations Kaspersky documented, and a later version of the malware could use others. For a second look, open System Settings > General > Login Items & Extensions and read through the background items for anything you didn’t install.
If you find something
Treat it as an incident, not a cleanup job. Work through these steps in order:
- Disconnect the Mac from the internet.
- From a different, clean device, move funds out of any wallet whose recovery phrase or password was on this Mac, typed into it or stored on it, into a new wallet with a new recovery phrase. If you only ever approved transactions on your hardware wallet’s screen and never typed the phrase anywhere, your keys are probably safe, but move the funds anyway if you have any doubt.
- Change your passwords from the clean device, starting with email, your Apple Account and exchanges. Sign out of all sessions, because browser cookies were stolen.
- Rotate developer credentials: SSH keys, cloud access keys and tokens. MacSync takes these too.
- Erase the Mac and reinstall macOS. Don’t try to clean it by hand; the backdoor is built to reinstall itself. Restore documents, not apps, from a backup made before the infection.
Habits that keep this from happening
- Get wallet apps only from the maker’s own website, typed into the address bar. Search ads are where fake download pages tend to turn up.
- Never type a recovery phrase into any app or website on a computer. No legitimate wallet app needs it to fix a problem.
- Confirm receiving addresses and amounts on your hardware wallet’s own screen, not only on the computer.
- Skip cracked software. It’s a delivery route MacSync has used before.
- Treat any password prompt from an app you just opened with suspicion until you know exactly why it’s asking.
- Don’t paste commands into Terminal from a guide you can’t verify.
The short version
MacSync arrives as a fake or cracked app, asks for your Mac password, pretends to be damaged, then installs a backdoor disguised as Finder that can swap your Ledger app. The iCloud calendar is a delivery trick, not your account being hacked. Check your Ledger and Trezor apps with codesign and spctl, look for the backdoor’s files, and never type a recovery phrase into any app on a computer.