Skip to content

Kaspersky warns of MacSync malware

Cajnewsafrica • September 17, 2026

by AKANI CHAUKE JOHANNESBURG, (CAJ News) – CYBERSECURITY researchers have uncovered an updated version of MacSync malware targeting macOS users, capable of stealing credentials, personal data and cryptocurrency assets.

Kaspersky researchers said the sophisticated infostealer, first identified in 2024-2025 as a variant of the AMOS stealer, had undergone significant changes.

The latest version, detected in September 2026, uses a more complex infection chain to install two key components – an infostealer and a backdoor – on victims’ devices.

The attack begins when users download a malicious file disguised as a legitimate application, potentially a document-sharing tool, cryptocurrency wallet or other software.

The malware then triggers additional downloads and manipulations. In some cases, researchers found that one malicious component was hosted in a public iCloud calendar entry in \*.ics format.

Once installed, the infostealer masquerades as the application the victim believes they have downloaded and asks for the administrator’s password.

After the password is entered, a fake notification claims the application is “damaged” and suggests moving it to the bin, distracting the victim while the malware operates.

MacSync can harvest browser histories, cookies and saved credentials, as well as data from cryptocurrency wallet applications, Telegram, the device’s login credentials and the Keychain file.

It can also collect information installed applications, device models and hardware, alongside SSH and ZSH configurations and other data.

The backdoor is disguised as the legitimate Finder application and gives attackers remote access to the device and its data.

According to Kaspersky, attackers can use the backdoor to deploy modified browser add-ons, potentially replacing legitimate cryptocurrency wallet extensions with malicious versions.

They can also replace the genuine Ledger cryptocurrency wallet application with a malicious clone, collect system information and specific files, and potentially execute arbitrary code.

Sergey Puzan, a security expert at Kaspersky, said the latest MacSync version differed significantly from earlier iterations, with new capabilities and a more complex infection chain.

He urged users to remain vigilant when installing applications, particularly software from unfamiliar developers, and to verify applications through trusted sources.

Puzan also warned users to treat administrator passwords as highly sensitive credentials and exercise caution when applications request them.

Kaspersky said its security solutions detect and neutralise threats associated with the MacSync malware family.

The company said more detailed information on the updated malware would be published on Securelist.com in the coming days.

Extracted Entities

Attack Types (1)

Domains (1)

Platforms (1)