Kaspersky has discovered an upgraded version of MacSync, a macOS infostealer that steals credentials, browsing data and crypto assets from infected devices. The new variant, spotted in September 2026, adds a more complex infection chain and a backdoor component that gives attackers remote access to a victim’s browser.
MacSync first appeared in 2024–2025 as an offshoot of the AMOS stealer family. Kaspersky says this latest version marks a significant rework, delivering both an infostealer and a backdoor in a single infection chain.
How the MacSync infection starts
The attack begins when a user downloads a file disguised as a legitimate app — a document-sharing tool, a crypto wallet, or something similar. In some cases, one of the malicious files in the chain is hosted inside a public iCloud calendar entry saved in .ics format.
Once installed, the infostealer opens looking like the app the victim thought they downloaded. It asks for the administrator password to continue, then shows a fake “app is damaged” notification urging the user to move it to the bin — a distraction technique while the malware works in the background. From there, it pulls browser history, cookies, saved credentials, crypto wallet data, Telegram data, device login details, the Keychain file, SSH and ZSH configs, plus a list of installed apps and hardware information.
A backdoor disguised as Finder
The second component, disguised as the macOS Finder app, gives attackers a backdoor into the device. Through it, they can deploy modified browser add-ons — most likely to swap out crypto wallet extensions for malicious versions — replace the legitimate Ledger wallet app with a fake clone, pull system information or specific files, and potentially run arbitrary code.
“The newly discovered version of the MacSync infostealer differs significantly from its previous versions, introducing new features and making the infection chain more complex,” said Sergey Puzan, security expert at Kaspersky.
Kaspersky is advising users to check that any app they install comes from its original developer and to verify legitimacy through trusted sources before entering an administrator password. The company says its security products already detect and block MacSync. Further technical detail is expected on Securelist in the coming days.



Share your thoughts