Mac Says an App ‘Is Damaged’? It Could Be MacSync Malware

0Shares

A Mac app that says it “is damaged” may not be broken at all. Kaspersky researchers say that message can be part of an updated macOS malware called MacSync. The message appears right after the user types in the administrator password.

MacSync is a macOS infostealer. It first emerged in 2024–2025 as a variant of the AMOS stealer. Kaspersky says the latest version, spotted in September 2026, uses a new, more complex infection chain and delivers an infostealer and a backdoor.

The MacSync backdoor can give attackers access to user files, system information and browser add-ons, including crypto wallet extensions.
The MacSync backdoor can give attackers access to user files, system information and browser add-ons, including crypto wallet extensions.

How MacSync Malware Infects Macs and Steals Data

The attack starts with a malicious file on a user’s device. This may happen when the user downloads malware disguised as an app, such as a document sharing app or a crypto wallet app. That triggers a series of further malicious downloads.

In some cases, one of those downloads is hosted in a public iCloud calendar entry in .ics format. The infection then installs MacSync’s core components: an infostealer and a backdoor.

When launched, the infostealer looks like the app the user thought they had downloaded. It asks for the administrator account password. After the password is entered, a notice says the app “is damaged” and suggests moving it to the trash.

Kaspersky says that alert is a technique intended to distract the user. The stealer collects web browser data, including browsing history, cookies and saved credentials. It also takes data from crypto wallet apps and Telegram messenger.

The stealer also collects the device’s login and password and the Keychain file. It gathers the list of installed apps, plus the device’s model and hardware data. SSH and ZSH configs and other data are also taken.

MacSync Backdoor Risks and Kaspersky’s Mac Security Advice

The second component, a backdoor, is disguised as the legitimate Finder app. It gives attackers access to the user’s data.

Attackers can remotely deploy modified add-ons in the user’s web browser, most likely to replace crypto wallet extensions with malicious ones. They can also replace the legitimate Ledger crypto wallet app with a malicious clone.

Related Post:  Kaspersky Warns: Your Phone Is the New Cybercrime Battleground

The backdoor can also collect system information or specific user files. Attackers could possibly execute arbitrary code for other purposes.

Sergey Puzan, security expert at Kaspersky, said the new version marks a big change. “The newly discovered version of the MacSync infostealer differs significantly from its previous versions, introducing new features and making the infection chain more complex.”

Puzan also warned about attackers’ tactics. “Threat actors are also actively developing social engineering techniques that serve as the initial access window to the victim’s device,

“and it is important to stay vigilant when installing new applications, especially if the app developer is not trusted,” he said. He then turned to advice for users.

Puzan recommended a simple habit. “We recommend to always check if the app you are downloading or installing is from the original developer, verifying its legitimacy via trusted sources.”

He also urged caution with the administrator password. “Your administrator password is the key protecting the most sensitive data and credentials on the device, and users should be alert when applications ask for it,” Puzan said.

Kaspersky says its security solutions successfully detect and neutralize threats associated with the MacSync malware family. More detailed information on the updated malware will be available on Securelist in the coming days.

0Shares

Leave a Reply