Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

MacSync malware steals passwords and crypto wallet data

Дата публикации: 21-09-2026 13:36:53

Kaspersky researchers have found a new version of MacSync malware that can steal passwords and cryptocurrency wallet data from macOS users. It also installs a backdoor that allows attackers to return to an infected Mac and make further changes. “The newly discovered version of the MacSync infostealer differs significantly from its previous versions, introducing new […]
The post MacSync malware steals passwords and crypto wallet data appeared first on Back End News.


Основное содержимое страницы с новостью.

Kaspersky researchers have found a new version of MacSync malware that can steal passwords and cryptocurrency wallet data from macOS users. It also installs a backdoor that allows attackers to return to an infected Mac and make further changes.

“The newly discovered version of the MacSync infostealer differs significantly from its previous versions, introducing new features and making the infection chain more complex,” said Sergey Puzan, security expert at Kaspersky. “Threat actors are also actively developing social engineering techniques that serve as the initial access window to the victim’s device, and it is important to stay vigilant when installing new applications, especially if the app developer is not trusted.”

The version, spotted in September 2026, shows a change from earlier MacSync malware, which emerged in 2024–2025 as a variant of the AMOS stealer. Its attack now involves several downloads before installing two main components: a tool that steals information and a backdoor that gives attackers continued access.

The infection can start when a user downloads malware disguised as an app, such as a document-sharing tool or a cryptocurrency wallet. In some cases, a later download in the attack is hosted in a public iCloud calendar entry, Kaspersky said.

Once installed, the information-stealing component opens as the app the user expected to see and asks for the Mac administrator password. After the user enters it, the app displays a message saying it “is damaged” and suggests moving it to the bin.

By then, the malware can collect saved browser passwords, cookies, browsing history, cryptocurrency wallet data, and Telegram data. Kaspersky said it can also take the device’s login details and Keychain file, which stores passwords and other sensitive information.

The backdoor poses as Finder, the app Mac users rely on to browse files. According to Kaspersky, it can let attackers collect files and system information, add modified browser extensions, or replace the legitimate Ledger cryptocurrency wallet app with a malicious copy. Kaspersky said the backdoor may also be used to run other code.

For people and businesses that use Macs to manage accounts or cryptocurrency, a stolen administrator password and an active backdoor could expose more than the data taken during the initial infection.

Puzan advised users to check that an app comes from its original developer and to be cautious when an app requests an administrator password. Kaspersky said its security products detect threats associated with the MacSync malware family.

Post navigation

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1MacSync macOS Stealer Returns With Binary Payloads and iCloud Tricks01325-09-2026
2Data security hinders Philippine AI adoption, Synology finds08.0301-10-2026
3Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor08.0129-09-2026
4Аферисты придумали новый способ кражи денег через поиск картинок09.2203-10-2026
5 Comment on Kaspersky finds 250,000 GitHub Actions security issues by Kaspersky finds torrent malware infecting users and businesses | Back End News 013.3301-10-2026
6Cyble: Ransomware attacks reach 2026 high in August011.2529-09-2026
7Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M010.1928-09-2026
8Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks07.9328-09-2026
9Attackers exploit zero-days in consistently besieged SonicWall product013.4603-09-2026
10China-linked hackers backdoored executives' laptops via USB, exploiting a fix companies had but weren't using010.403-09-2026

Классификация: Пресс-релизы. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 5.87. Источник: backendnews.net.