www.pantau.com New MacSync Malware Variant Targets macOS Users' Crypto and Sensitive Data
Article Content
- •The new MacSync malware variant targets macOS users, stealing sensitive data.
- •It uses a complex infection chain, including malicious files disguised as legitimate applications.
- •A backdoor component allows remote access and modification of user data.
Kaspersky has identified a new variant of the MacSync malware, which targets macOS users by stealing sensitive information, including crypto wallet data and passwords. This infostealer, first seen in 2024-2025 as a variant of AMOS, has evolved to employ a more complex infection chain. The attack typically begins when users download malicious files disguised as legitimate applications, such as document sharing tools or crypto wallets. In some instances, the malware is delivered via public iCloud calendar entries formatted as .ics files. Once installed, it masquerades as the intended application and requests the administrator password. After gaining access, it collects various sensitive data, including browser cookies, saved credentials, and Telegram information. The malware also includes a backdoor component that allows attackers to remotely modify browser extensions and potentially replace legitimate crypto wallet applications with malicious clones. Kaspersky experts emphasize the need for users to be cautious when installing new applications, particularly from unknown developers.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track AMOS in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Infostealer Malware Hijacks Claude Sessions, Drains User Accounts Anthropic has alerted users that infostealer malware is compromising Claude accounts by hijacking active login sessions, allowing attackers to deplete usage limits without needing passwords or two-factor authentication. The malware, identified as Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, and Atomic…
HBO Max Account Compromise Fuels ClickFix Malware Campaign In September 2026, hackers compromised the verified HBO Max Reddit account, launching a ClickFix campaign that distributed 108 malicious ads over 48 hours. The ads targeted both macOS and Windows users, tricking them into executing commands that installed information-stealing malware. This operation, dubbed…