MalwareTips News MacSync malware targets Mac passwords, wallets and browser data through fake apps

Security News
0 Replies 121 Views

Where do you usually get apps for your Mac?

  • Mac App Store

    Votes: 0 0.0%
  • Official developer websites

    Votes: 0 0.0%
  • Several trusted sources

    Votes: 0 0.0%
  • Other download sites

    Votes: 0 0.0%
  • I do not use a Mac

    Votes: 0 0.0%

  • Total voters
    0

News Now

Happening Now
Verified
MalwareTips-news-108.jpg

Image: Kaspersky researchers

Mac users who install cracked software or unfamiliar apps face a changing threat from MacSync, malware designed to steal passwords, wallet data and other sensitive files. A newly observed version can also install a backdoor that gives attackers an ongoing route into the Mac.


Fake and cracked apps start the attack​

Kaspersky researchers first found this infection chain in the wild in September 2026. MacSync operators have spread the malware as free or cracked versions of popular software and as invented products, including a fake crypto wallet called Toria promoted on X and Telegram.

The latest campaign starts with malicious DMG disk images. Its files support both Apple silicon and Intel Macs, widening the range of potentially affected devices.

What MacSync can take​

The stealer asks for the administrator password in a window styled to match the app it is impersonating. After a password is entered, it displays a fake macOS message saying the application is corrupted and offers to move it to the Trash.

  • Browser history, cookies, saved logins and crypto wallet extension data
  • Crypto wallet app data, Telegram data, the Keychain file and the Mac login password
  • SSH, AWS, Kubernetes and Git configuration files, plus shell command history

Backdoor tries to stay hidden​

MacSync installs a backdoor disguised as Finder and creates several ways to restart it, including a LaunchAgent named com.apple.finder.agent. A LaunchAgent is a macOS mechanism that can automatically run software for a signed-in user.

A repair script can restore deleted backdoor files from a backup and recreate the LaunchAgent. It also stops macOS processes responsible for some background-item notifications, reducing the chance that the user sees an alert about the new startup entry.

Steps for Mac users​

  • Avoid cracked software and download apps from the Mac App Store or the developer's verified website; fake software is a documented MacSync delivery route.
  • If you entered your administrator password into a suspicious installer, change the Mac login password and important saved account passwords from a clean device.
  • Check System Settings for unfamiliar login or background items, and investigate com.apple.finder.agent or $HOME/Library/Application Support/System if present.
  • Run an updated security scan. Kaspersky products identify related samples under detection names beginning HEUR:Trojan.OSX.MacSync and HEUR:Trojan-PSW.OSX.MacSync.
 
Community
Security tip
Verify Windows 10 coverage. If you still use Windows 10, confirm your device is enrolled in an applicable Extended Security Updates program. Check current eligibility and coverage directly with Microsoft.
Back
Top