Kaspersky Finds New MacSync Malware Targeting Mac Users

One Identity Offers Free Security Risk Assessment to SolarWinds Customers and Free Safeguard for Proactive Privilege Defense

Kaspersky has discovered an upgraded version of MacSync, a macOS infostealer that steals credentials, browsing data and crypto assets from infected devices. The new variant, spotted in September 2026, adds a more complex infection chain and a backdoor component that gives attackers remote access to a victim’s browser.

MacSync first appeared in 2024–2025 as an offshoot of the AMOS stealer family. Kaspersky says this latest version marks a significant rework, delivering both an infostealer and a backdoor in a single infection chain.

How the MacSync infection starts

The attack begins when a user downloads a file disguised as a legitimate app — a document-sharing tool, a crypto wallet, or something similar. In some cases, one of the malicious files in the chain is hosted inside a public iCloud calendar entry saved in .ics format.

Once installed, the infostealer opens looking like the app the victim thought they downloaded. It asks for the administrator password to continue, then shows a fake “app is damaged” notification urging the user to move it to the bin — a distraction technique while the malware works in the background. From there, it pulls browser history, cookies, saved credentials, crypto wallet data, Telegram data, device login details, the Keychain file, SSH and ZSH configs, plus a list of installed apps and hardware information.

A backdoor disguised as Finder

The second component, disguised as the macOS Finder app, gives attackers a backdoor into the device. Through it, they can deploy modified browser add-ons — most likely to swap out crypto wallet extensions for malicious versions — replace the legitimate Ledger wallet app with a fake clone, pull system information or specific files, and potentially run arbitrary code.

“The newly discovered version of the MacSync infostealer differs significantly from its previous versions, introducing new features and making the infection chain more complex,” said Sergey Puzan, security expert at Kaspersky.

Kaspersky is advising users to check that any app they install comes from its original developer and to verify legitimacy through trusted sources before entering an administrator password. The company says its security products already detect and block MacSync. Further technical detail is expected on Securelist in the coming days.

Author


Discover more from techcoffeehouse.com

Subscribe to get the latest posts sent to your email.

Use promo code “TCH15” to get 15% off on checkout.

Share your thoughts

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Discover more from techcoffeehouse.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from techcoffeehouse.com

Subscribe now to keep reading and get access to the full archive.

Continue reading