Kaspersky discovers a new version of MacSync malware stealing credentials and crypto from macOS users

Kaspersky discovers a new version of MacSync malware stealing credentials and crypto from macOS users

Kaspersky researchers have discovered a sophisticated, updated version of the macOS infostealer known as MacSync. First emerging in 2024–2025 as a variant of the AMOS stealer, the malware has undergone a significant transformation. This latest version, spotted in September 2026, uses a new complex infection chain and delivers an infostealer and a backdoor to the victim’s device, compromising credentials, different types of user data, and crypto assets.

The attack begins with a malicious file ending up on a user’s device – this may be a result of the user downloading the malware disguised as a certain application (a document sharing app, crypto wallet app or other apps). This triggers a series of further malicious downloads and manipulations on the device. In some cases, one of the malicious downloads in the attack sequence is hosted in a public iCloud calendar entry in *.ics format. As a result of the infection, the core MacSync malware components are installed: an infostealer and a backdoor.

When launched, the infostealer appears as an application that the user thought they had downloaded. It prompts the user to enter the password for the administrator’s account. After the password is entered, a notification is displayed saying that the app “is damaged,” suggesting moving it to the bin – a technique intended to distract the user. The stealer collects web browser data (browsing history, cookies, saved credentials), data from crypto wallet apps, Telegram messenger data, the device’s login and password, and the Keychain file. It also collects the list of installed apps and the device’s model and hardware data, SSH, ZSH configs and other data.

Another MacSync component – the backdoor – is disguised as the legitimate Finder app and grants attackers access to the user’s data. Specifically, through this backdoor the attackers can remotely deploy modified add-ons in the user’s web browser (most likely to replace crypto wallet extensions with malicious ones), replace the legitimate Ledger crypto wallet app with a malicious clone, collect various system information or specific user files, and possibly execute arbitrary code for other purposes.

The newly discovered version of the MacSync infostealer differs significantly from its previous versions, introducing new features and making the infection chain more complex. Threat actors are also actively developing social engineering techniques that serve as the initial access window to the victim’s device, and it is important to stay vigilant when installing new applications, especially if the app developer is not trusted. We recommend to always check if the app you are downloading or installing is from the original developer, verifying its legitimacy via trusted sources. Your administrator password is the key protecting the most sensitive data and credentials on the device, and users should be alert when applications ask for it ,” comments Sergey Puzan, security expert at Kaspersky.

Kaspersky security solutions successfully detect and neutralize threats associated with the MacSync malware family.

More detailed information on the updated MacSync malware will be available on Securelist in the coming days.

 

About Kaspersky Threat Research

The Threat Research team is a leading authority in protecting against cyberthreats. By actively engaging in both threat analysis and technology creation, our TR experts ensure that Kaspersky’s cybersecurity solutions are deeply informed and exceptionally potent, providing critical threat intelligence and robust security to our clients and the broader community.

About Kaspersky

Kaspersky is a global cybersecurity and digital privacy company founded in 1997. Innovating the industry with a Cyber Immunity approach, Kaspersky safeguards consumers, businesses, critical infrastructure, and governments from cyberthreats, with over a billion devices protected to date.

Kaspersky ensures Cybersecurity True to Business, focusing on providing clear outcomes, protecting revenue, easing workloads and preventing downtime. Kaspersky’s deep threat intelligence and security expertise is constantly transforming into innovative solutions and services for organizations of every size, from small businesses to large enterprises, combining proven AI-driven protection technologies with simple management and expert support.

Recognized in independent tests and trusted by millions of individuals worldwide and nearly 200,000 organizations, Kaspersky helps detect threats earlier, respond faster and operate with greater confidence and freedom, protecting what matters most to our clients. Learn more at www.kaspersky.com.

 

You Must be Registered Or Logged in To Comment Log In?

PARTNER CONTENT

Mark and Com

A leading boutique public relations and communications agency based in Colombo, Sri Lanka. Founded in 2011, it offers strategic PR services, media relations, reputation management, stakeholder communications and integrated communications solutions for both local and multinational brands. The agency combines global expertise with deep local insight and is part of the GlobalCom PR Network, helping clients build influence, trust and meaningful impact. It has been recognized regionally, including winning the Rest of South Asia PR Agency of the Year award. 

Verified partner since January 2026.

Follow US