< Back to all clusters
[TECHNOLOGY] · 3 sources

started · updated

MacSync malware targets macOS users with new infostealer and backdoor

Kaspersky researchers have identified an upgraded version of MacSync, a macOS infostealer that uses a more complex infection chain to target Mac users. The malware, spotted in September 2026, delivers both an infostealer and a backdoor component.

The infection typically begins when a user downloads a file disguised as a legitimate application, such as a crypto wallet or document-sharing tool. In some instances, malicious files are hosted within public iCloud calendar entries in .ics format. Once the user provides their administrator password, the malware displays a fake “app is damaged” notification. This message is a distraction technique designed to trick users into moving the app to the trash while the malware operates in the background.

The infostealer component targets sensitive data, including web browser history, cookies, saved credentials, Telegram data, and cryptocurrency wallet information. It also collects device hardware data, Keychain files, and SSH/ZSH configurations.

Additionally, the malware includes a backdoor disguised as the legitimate macOS Finder app. This backdoor allows attackers to gain remote access to the device, enabling them to pull system information, access specific files, or deploy malicious browser add-ons to replace legitimate crypto wallet extensions with fraudulent versions.

Entities

Kaspersky · MacSync · macOS