Economynext Kaspersky Uncovers New MacSync Malware Targeting macOS Users
Article Content
- •New MacSync malware targets macOS users, stealing credentials and crypto assets.
- •The malware uses a complex infection chain, beginning with a malicious file download.
- •Kaspersky advises users to verify application sources and protect their administrator passwords.
Kaspersky has identified an updated version of MacSync malware, which targets macOS users to steal credentials and cryptocurrency assets. This sophisticated infostealer, first detected in 2024-2025 as a variant of the AMOS stealer, employs a complex infection chain. The attack begins with users downloading a malicious file disguised as a legitimate application, which then triggers additional malicious downloads. The malware installs two main components: an infostealer and a backdoor, with the latter disguised as the Finder application. Once operational, the infostealer collects sensitive data, including browser histories, saved credentials, and information from cryptocurrency wallets. Kaspersky warns users to verify application legitimacy and treat administrator passwords with caution. The latest version was detected in September 2026, and Kaspersky plans to release more information on Securelist.com soon.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track AMOS Stealer in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
HBO Max Account Compromise Fuels ClickFix Malware Campaign In September 2026, hackers compromised the verified HBO Max Reddit account, launching a ClickFix campaign that distributed 108 malicious ads over 48 hours. The ads targeted both macOS and Windows users, tricking them into executing commands that installed information-stealing malware. This operation, dubbed…
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…