Skip to content
New MacSync Malware Variant Targets macOS Users' Crypto and Sensitive Data

New MacSync Malware Variant Targets macOS Users' Crypto and Sensitive Data

First seen 21 Sep 2026, 16:53 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 21, 2026 at 18:54 UTC
  • The new MacSync malware variant targets macOS users, stealing sensitive data.
  • It uses a complex infection chain, including malicious files disguised as legitimate applications.
  • A backdoor component allows remote access and modification of user data.

Kaspersky has identified a new variant of the MacSync malware, which targets macOS users by stealing sensitive information, including crypto wallet data and passwords. This infostealer, first seen in 2024-2025 as a variant of AMOS, has evolved to employ a more complex infection chain. The attack typically begins when users download malicious files disguised as legitimate applications, such as document sharing tools or crypto wallets. In some instances, the malware is delivered via public iCloud calendar entries formatted as .ics files. Once installed, it masquerades as the intended application and requests the administrator password. After gaining access, it collects various sensitive data, including browser cookies, saved credentials, and Telegram information. The malware also includes a backdoor component that allows attackers to remotely modify browser extensions and potentially replace legitimate crypto wallet applications with malicious clones. Kaspersky experts emphasize the need for users to be cautious when installing new applications, particularly from unknown developers.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2024-01-01
MacSync malware first identified
The original MacSync malware variant emerged as a modification of the AMOS infostealer.
wartaekonomi.co.id
2026-09-21
New MacSync variant detected
Kaspersky reports a new variant of MacSync with enhanced capabilities targeting macOS users.
pantau.com
2026-09-21
Kaspersky issues security warning
Kaspersky advises macOS users to exercise caution when downloading applications from unknown sources.
jpnn.com

More articles in this cluster (3)

Following this threat?

Track AMOS in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed