KASPERSKY DISCOVERS NEW VERSION OF MACSYNC MALWARE STEALING CREDENTIALS AND CRYPTO FROM MACOS USERS

TechnologyCybersecurityKASPERSKY DISCOVERS NEW VERSION OF MACSYNC MALWARE STEALING CREDENTIALS AND CRYPTO FROM...

Kaspersky researchers have discovered an updated version of MacSync, a macOS infostealer that has evolved from earlier variants first seen in 2024 and 2025.

The new version, spotted in September 2026, uses a more complex infection chain and installs two main components on affected devices: an infostealer designed to collect sensitive data and a backdoor that can give attackers further access to the system.

MALWARE CAN ARRIVE DISGUISED AS LEGITIMATE APPS

According to Kaspersky, an attack can begin when a user downloads a malicious file disguised as a legitimate application, such as a document-sharing app, crypto wallet, or another type of software.

That initial download can trigger additional malicious files and system changes. In some cases, researchers observed that one of the malicious downloads was hosted inside a public iCloud calendar entry using the .ics format.

Once the infection chain completes, the MacSync infostealer and backdoor install on the Mac.

FAKE PASSWORD PROMPTS HELP STEAL CREDENTIALS

MacSync malware macOS

When launched, the infostealer can appear as the application the user intended to install.

It then prompts the user to enter the administrator account password. After the password is entered, the app displays a message saying it is “damaged” and should be moved to the bin, a distraction technique intended to make the failed installation appear legitimate.

MacSync malware macOS

The stealer can collect browser history, cookies, saved credentials, crypto wallet data, Telegram data, the Mac’s login and password information, and the Keychain file.

It can also gather information about installed applications and hardware, along with SSH and ZSH configuration files and other system data.

BACKDOOR CAN MODIFY APPS AND BROWSER EXTENSIONS

A separate MacSync component is disguised as the legitimate Finder application.

Kaspersky says the backdoor can allow attackers to deploy modified browser add-ons, potentially replacing crypto wallet extensions with malicious versions. It can also replace the legitimate Ledger crypto wallet app with a malicious clone.

The backdoor can also collect system information and specific user files and may allow attackers to execute arbitrary code for other purposes.

SOCIAL ENGINEERING REMAINS THE ENTRY POINT

“The newly discovered version of the MacSync infostealer differs significantly from its previous versions, introducing new features and making the infection chain more complex,” said Sergey Puzan, security expert at Kaspersky.

He added that attackers are continuing to develop social engineering techniques to gain initial access to users’ devices.

Kaspersky advises users to be cautious when installing applications, particularly when the developer is unfamiliar. Users should verify that software comes from the original developer and confirm its legitimacy through trusted sources before installation.

Administrator password requests also deserve particular attention, since granting those credentials can give malicious software access to sensitive system data.

MORE DETAILS TO FOLLOW

Kaspersky says its security products detect and neutralize threats associated with the MacSync malware family.

The company plans to publish more detailed technical information about the updated MacSync malware through Securelist in the coming days.

More information on Kaspersky’s security research is available through the Kaspersky website.

Related Posts