
Mac users are being warned about an updated malware strain that can steal passwords, browser data, crypto wallet information, and other sensitive files from infected devices.
Kaspersky researchers have discovered a new version of MacSync, a macOS infostealer first seen in 2024–2025 as a variant of the AMOS stealer. Spotted in September 2026, the updated malware uses a more complex infection chain and installs two components: an infostealer and a backdoor.
The attack starts when users download a malicious file disguised as a legitimate application, such as a document-sharing tool or crypto wallet app. The malware can then trigger additional downloads and system manipulations. In some cases, one of these files is hosted through a public iCloud calendar entry in .ics format.
Once installed, the infostealer can mimic the app the user intended to download and prompt them for an administrator password. Afterward, it may display a message claiming the app is “damaged” and suggest moving it to the bin—an apparent distraction while the malware continues operating.
MacSync can collect browser history, cookies, saved credentials, crypto wallet data, Telegram information, device login credentials, the Keychain file, installed-app lists, hardware details, and SSH and ZSH configurations.
The backdoor, meanwhile, disguises itself as the legitimate Finder app. It can give attackers remote access to system information and files, as well as allow them to deploy modified browser add-ons. Kaspersky says these could potentially be used to replace crypto wallet extensions with malicious versions or swap a legitimate Ledger app with a fake one.
“The newly discovered version of the MacSync infostealer differs significantly from its previous versions, introducing new features and making the infection chain more complex,” said Kaspersky security expert Sergey Puzan.
Kaspersky advises Mac users to stay vigilant when installing applications, particularly those from unfamiliar developers.

















