Kaspersky researchers have found a new version of MacSync malware that can steal passwords and cryptocurrency wallet data from macOS users. It also installs a backdoor that allows attackers to return to an infected Mac and make further changes.

“The newly discovered version of the MacSync infostealer differs significantly from its previous versions, introducing new features and making the infection chain more complex,” said Sergey Puzan, security expert at Kaspersky. “Threat actors are also actively developing social engineering techniques that serve as the initial access window to the victim’s device, and it is important to stay vigilant when installing new applications, especially if the app developer is not trusted.”

The version, spotted in September 2026, shows a change from earlier MacSync malware, which emerged in 2024–2025 as a variant of the AMOS stealer. Its attack now involves several downloads before installing two main components: a tool that steals information and a backdoor that gives attackers continued access.

The infection can start when a user downloads malware disguised as an app, such as a document-sharing tool or a cryptocurrency wallet. In some cases, a later download in the attack is hosted in a public iCloud calendar entry, Kaspersky said.

Once installed, the information-stealing component opens as the app the user expected to see and asks for the Mac administrator password. After the user enters it, the app displays a message saying it “is damaged” and suggests moving it to the bin.

By then, the malware can collect saved browser passwords, cookies, browsing history, cryptocurrency wallet data, and Telegram data. Kaspersky said it can also take the device’s login details and Keychain file, which stores passwords and other sensitive information.

The backdoor poses as Finder, the app Mac users rely on to browse files. According to Kaspersky, it can let attackers collect files and system information, add modified browser extensions, or replace the legitimate Ledger cryptocurrency wallet app with a malicious copy. Kaspersky said the backdoor may also be used to run other code.

For people and businesses that use Macs to manage accounts or cryptocurrency, a stolen administrator password and an active backdoor could expose more than the data taken during the initial infection.

Puzan advised users to check that an app comes from its original developer and to be cautious when an app requests an administrator password. Kaspersky said its security products detect threats associated with the MacSync malware family.

Leave a Reply

Discover more from Back End News

Subscribe now to keep reading and get access to the full archive.

Continue reading