
Kaspersky cybersecurity researchers have uncovered a heavily modified version of the MacSync infostealer that deploys a dual-threat attack against macOS users to hijack credentials, system files, and cryptocurrency assets.
First detected between 2024 and 2025 as a derivative of the AMOS stealer family, the upgraded malware variant identified in September 2026 features a far more complex infection chain. Once executed, the routine drops both a primary infostealer and a hidden backdoor onto compromised Apple devices.
Initial access relies heavily on social engineering. Victims are tricked into downloading malicious files disguised as legitimate software, including document-sharing programs, cryptocurrency wallet applications, or other everyday tools. In certain cases, attackers host one of the payload downloads inside a public iCloud calendar entry formatted as an .ics file.
Once the initial payload lands on the machine, the core MacSync components begin installation:
- Admin Password Extraction: The infostealer opens under the guise of the expected application and prompts the user to enter their administrator password.
- Distraction Routine: After receiving the password, the app displays a fake notification claiming the application “is damaged” and suggests moving it to the Bin.
- System-Wide Data Theft: While the user assumes the download failed, the stealer harvests browser data (history, cookies, saved credentials), local crypto wallet information, Telegram messenger databases, SSH and ZSH configuration files, installed application lists, system hardware metrics, and the macOS Keychain file.
Alongside the stealer, the malware drops a backdoor component disguised as the legitimate macOS Finder application. This covert entry point provides attackers with deep remote access to the host machine.
Through the backdoor, threat actors can deploy modified browser add-ons designed to replace legitimate cryptocurrency wallet extensions with malicious clones. The access also enables attackers to swap the authentic Ledger desktop app with a tampered version, exfiltrate targeted files, pull system configuration details, and run arbitrary commands.
“The newly discovered version of the MacSync infostealer differs significantly from its previous versions, introducing new features and making the infection chain more complex. Threat actors are also actively developing social engineering techniques that serve as the initial access window to the victim’s device, and it is important to stay vigilant when installing new applications, especially if the app developer is not trusted. We recommend to always check if the app you are downloading or installing is from the original developer, verifying its legitimacy via trusted sources. Your administrator password is the key protecting the most sensitive data and credentials on the device, and users should be alert when applications ask for it ,” comments Sergey Puzan, security expert at Kaspersky.
Kaspersky confirmed that its security software detects and blocks threats connected to the MacSync family. Detailed technical analysis of the updated variant is scheduled for release on Securelist.







Leave a Reply