Fresh MacSync Threat Hits macOS
Kaspersky has identified a significantly updated version of the MacSync infostealer, first seen as an AMOS variant in 2024-2025. The September 2026 sample uses a longer infection chain that drops both an infostealer and a backdoor onto victims’ devices. The malware focuses on stealing login details, browser data, crypto assets and system information from macOS users.
How the Attack Unfolds
Infection usually starts when someone downloads what looks like a legitimate app such as a document tool or crypto wallet. The malware then pulls further files, sometimes hosted inside a public iCloud calendar entry in .ics format. Once running, the infostealer poses as the expected application and asks for the administrator password. It then shows a fake “damaged app” message to distract the user while it works in the background.
Data the Malware Collects
The stealer grabs browsing history, cookies, saved passwords, crypto-wallet files, Telegram data, the Keychain, SSH and ZSH configs, plus hardware details. A separate backdoor component, disguised as Finder, lets attackers swap browser extensions, replace the Ledger wallet app with a fake version, and run further commands.
What Kaspersky Advises
As we noted in our piece on Kaspersky’s recent business security updates, the firm continues to strengthen its detection of this family. Sergey Puzan, security expert at Kaspersky, said: “The newly discovered version of the MacSync infostealer differs significantly from its previous versions, introducing new features and making the infection chain more complex. Threat actors are also actively developing social engineering techniques that serve as the initial access window to the victim’s device, and it is important to stay vigilant when installing new applications, especially if the app developer is not trusted. We recommend to always check if the app you are downloading or installing is from the original developer, verifying its legitimacy via trusted sources. Your administrator password is the key protecting the most sensitive data and credentials on the device, and users should be alert when applications ask for it.”
Kaspersky’s solutions already detect the updated MacSync components. For broader privacy protection on macOS, compare options in our VPN section.








