Welcome

Join the leading Carding Forum for carders worldwide. Connect, discuss, and explore carding topics and free carding stuff like cc, dumps with pin, leaked deatabse, bank accounts and much more in a trusted community hub for beginners and pros.

  • Contact : for Purchasing Advertisement and TELEGRAM : @Cardersforum_Admin
adv ex on 22 February 2024

Pro Carders

Admin
Staff member
Joined
Apr 5, 2024
Messages
155
Points
28
New version of MacSync stealer steals passwords and crypto wallet data from macOS usersSeptember 18, 2026
It uses a more complex, multi-stage infection chain.

Kaspersky Lab experts have identified an updated variant of the MacSync stealer targeting macOS devices. The malware emerged in 2024-2025 as a fork of the AMOS stealer, but has since evolved significantly. The new version, discovered in September 2026, uses a more complex, multi-stage infection chain. This installs a stealer designed to steal passwords, cryptocurrency, and sensitive user data, as well as a backdoor that grants attackers remote access to the infected device.

Attack initiation. The initial malicious file can be delivered to the device by downloading malware disguised as an app the user intended to download—for example, a document collaboration service or a cryptocurrency wallet. This file initiates a chain of subsequent downloads and manipulations on the device. In some cases, one of the components was placed in a publicly accessible iCloud calendar entry in *.ics format. The infection installs key MacSync components on the device: a stealer and a backdoor.

How the stealer appears and what it steals. After installation, the stealer, disguised as an app the user wanted to download, requests an administrator password. If the password is entered, a fake notification appears stating that the app is corrupted and offering to move it to the Trash. MacOS typically displays this notification when the user attempts to launch a genuinely corrupted app, but in this case, the notification is generated by malware, and nothing is actually moved to the Trash. The stealer remains on the device and collects browser history, cookies, saved logins and passwords, and data from crypto wallet apps and the Telegram messenger. It also collects a list of installed apps, device model and hardware information, SSH and ZSH settings, and other information.

How the backdoor appears and what it does. Another MacSync component—the backdoor—disguises itself as the legitimate Finder, the default macOS file manager. One of its functions is the ability to remotely install any browser extension on an infected device, most likely designed to steal cryptocurrency. Furthermore, attackers can replace the legitimate Ledger crypto wallet app with a malicious one, collect system information or individual user files, and execute arbitrary code.

"The new version of the MacSync stealer differs significantly from previous modifications with a more complex infection chain and the introduction of new features. Attackers are constantly adapting social engineering techniques that allow them to gain initial access to a victim's device, so it's important to be vigilant when installing new applications, especially if the developer is untrustworthy. We recommend always verifying that the application you're downloading is indeed from the original developer and verifying its reliability by using trusted sources. An administrator password is a key element in protecting sensitive data and credentials on a device, so be especially careful when applications request it,"
 
Top