Kaspersky researchers have uncovered a significantly updated version of the “MacSync” malware targeting macOS users, capable of stealing browser credentials, Keychain data, Telegram data, and cryptocurrency assets. First identified in 2024 as a variant of the AMOS stealer, this new MacSync iteration spotted in September 2026 introduces a more complex infection chain and delivers both an infostealer and a backdoor onto victim devices.
How MacSync Works
The attack begins when a user downloads a malicious file disguised as a legitimate application, such as a document sharing app or a crypto wallet app. Once executed, the file triggers a chain of further malicious downloads. In some cases, one of these downloads is hosted inside a public iCloud Calendar entry in .ics format, demonstrating how attackers are exploiting trusted platforms as part of the delivery mechanism.


Once installed, the infostealer presents itself as the application the user intended to download; it then prompts the user to enter their administrator account password. After the password is entered, a fake notification appears claiming the app is damaged and suggests moving it to the bin, a distraction technique designed to deflect suspicion while the malware operates in the background.
The infostealer collects web browser data including browsing history, cookies, and saved credentials, along with data from crypto wallet apps, Telegram, SSH and ZSH configurations, the device’s Keychain file, the list of installed applications, and hardware information.
A second component of the MacSync malware is a backdoor disguised as the legitimate macOS Finder application. Through this backdoor, attackers can remotely deploy modified browser add-ons, most likely to swap out legitimate crypto wallet extensions with malicious ones. It can also replace the genuine Ledger hardware wallet app with a malicious clone, collect system information or specific user files, and potentially execute arbitrary code on the compromised device.
Kaspersky says its security solutions are confirmed to detect and neutralize threats from the MacSync malware family – a more detailed technical breakdown of the updated malware is set to be published on its Securelist blog in the coming days.
Pokdepinion: The moving to Bin bit is a sneaky one.

