Skip to content
Kaspersky Uncovers New MacSync Malware Targeting macOS Users

Kaspersky Uncovers New MacSync Malware Targeting macOS Users

First seen 19 Sep 2026, 19:58 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 20, 2026 at 00:24 UTC
  • New MacSync malware targets macOS users, stealing credentials and crypto assets.
  • The malware uses a complex infection chain, beginning with a malicious file download.
  • Kaspersky advises users to verify application sources and protect their administrator passwords.

Kaspersky has identified an updated version of MacSync malware, which targets macOS users to steal credentials and cryptocurrency assets. This sophisticated infostealer, first detected in 2024-2025 as a variant of the AMOS stealer, employs a complex infection chain. The attack begins with users downloading a malicious file disguised as a legitimate application, which then triggers additional malicious downloads. The malware installs two main components: an infostealer and a backdoor, with the latter disguised as the Finder application. Once operational, the infostealer collects sensitive data, including browser histories, saved credentials, and information from cryptocurrency wallets. Kaspersky warns users to verify application legitimacy and treat administrator passwords with caution. The latest version was detected in September 2026, and Kaspersky plans to release more information on Securelist.com soon.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2024-01-01
MacSync malware first identified
MacSync malware emerged as a variant of the AMOS stealer, targeting macOS users.
Cajnewsafrica
2026-09-01
New version of MacSync detected
Kaspersky researchers discovered an updated version of MacSync malware with enhanced capabilities.
Cajnewsafrica
2026-09-19
Kaspersky publishes findings
Kaspersky released details about the new MacSync malware, urging users to stay vigilant.
Economynext

More articles in this cluster (2)

Following this threat?

Track AMOS Stealer in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed