Industry & Sector NewsTechnology & Digital Services

⚠️ Cybersecurity Alert: Upgraded MacSync Malware Threats 💻

Source

• Overview & Threat Scope Kaspersky discovered an upgraded version of the MacSync infostealer targeting macOS users to extract credentials, user data, and crypto assets. The strain uses a complex infection chain paired with a backdoor to compromise devices. • Infection Vectors & Tactics • Disguised apps (document sharing, crypto wallets) serve as initial entry points. • Malicious payloads are sometimes hosted in public iCloud calendar entries (.ics format). • Stealer prompts users for admin passwords, then displays a false "app is damaged" error to distract victims. • Compromised Systems & Data • Infostealer: Extracts browser history, cookies, saved logins, crypto wallet credentials, Telegram data, Keychain files, and hardware info. • Backdoor: Disguised as the legitimate Finder app, enabling hackers to remotely execute code, inject malicious browser add-ons, or replace apps like Ledger with malicious clones. • Key Mitigation Verify developers via trusted sources before installing apps. Treat administrator password prompts with extreme caution, as they grant full access to sensitive systems.

Listen to this article

Duration: 1:53