• Home  
  • Kaspersky warns of upgraded MacSync macOS malware
- Enterprise Technology - News

Kaspersky warns of upgraded MacSync macOS malware

Kaspersky researchers identified an upgraded MacSync malware campaign that combines an infostealer and backdoor to target macOS users. Kaspersky researchers have identified a significantly upgraded version of the MacSync infostealer, a macOS malware family that can steal credentials, personal data and cryptocurrency assets while giving attackers remote access to compromised devices. First seen in 2024–2025 […]

Kaspersky researchers identified an upgraded MacSync malware campaign that combines an infostealer and backdoor to target macOS users.

Kaspersky researchers have identified a significantly upgraded version of the MacSync infostealer, a macOS malware family that can steal credentials, personal data and cryptocurrency assets while giving attackers remote access to compromised devices.

First seen in 2024–2025 as a variant of the AMOS stealer, the updated MacSync was detected in September 2026 and now uses a more complex infection chain that installs two key components: an infostealer and a backdoor.

Malware disguises itself as legitimate apps

The attack begins when users download a malicious file disguised as a legitimate application, such as a document-sharing or cryptocurrency wallet app. The infection can trigger multiple malicious downloads and manipulations, with Kaspersky noting that some payloads have been hosted through public iCloud Calendar entries in .ics format.

The infostealer is designed to appear as the application the victim intended to install. It then requests the user’s administrator password. After the password is entered, the malware displays a message claiming the application is “damaged” and suggests moving it to the Trash, potentially helping conceal the compromise.

Fake notifications used by the infostealer

MacSync can harvest browser histories, cookies, saved credentials, cryptocurrency wallet data, Telegram information, device login credentials and the macOS Keychain file. It can also collect installed-application lists, hardware information, SSH and ZSH configurations and other system data.

Backdoor enables remote access

A second component is disguised as the legitimate Finder application. The backdoor can provide attackers with access to system and user data and enable additional malicious activity.

According to Kaspersky, attackers can remotely deploy modified browser add-ons, potentially targeting cryptocurrency wallet extensions, replace the legitimate Ledger wallet application with a malicious copy, collect system information and specific files, and potentially execute arbitrary code.

Kaspersky security solutions detect and neutralize threats associated with the MacSync malware family.

The security company is advising macOS users to exercise caution when installing applications, particularly those from unfamiliar developers, and to verify software through trusted sources. Users should also be especially cautious when an application unexpectedly requests an administrator password.

The latest MacSync findings underscore how macOS malware is evolving beyond simple information theft by combining social engineering, credential theft, cryptocurrency targeting and persistent remote access in a single attack chain.

Email Us

For inquiries, press releases, and partnership request, get in touch with us at: info.aitimes.ph@gmail.com.

Contact: 0956-344-3286

AI Times  @2026. All Rights Reserved.