LmCast :: Stay tuned in

MacSync malware uses public iCloud calendars to deliver new payloads

Recorded: Sept. 24, 2026, 9:10 p.m.

Original Summarized

MacSync malware uses public iCloud calendars to deliver new payloads

News

Featured
Latest

ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach

New Windows Defender zero-day blocks Microsoft antivirus updates

EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts

Check Point warns of Management Server zero-day exploited in attacks

MacSync malware uses public iCloud calendars to deliver new payloads

New Carbonato malware uses AI agents to hijack exposed Docker hosts

Drop monthly subscriptions with a $79.99 lifetime PDF editor for Mac

Exposed GitLab project email addresses let attackers push code

Tutorials

Latest
Popular

How to access the Dark Web using the Tor Browser

How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11

How to use the Windows Registry Editor

How to backup and restore the Windows Registry

How to start Windows in Safe Mode

How to remove a Trojan, Virus, Worm, or other Malware

How to show hidden files in Windows 7

How to see hidden files in Windows

Webinars
Downloads

Latest
Most Downloaded

Qualys BrowserCheck

STOPDecrypter

AuroraDecrypter

FilesLockerDecrypter

AdwCleaner

ComboFix

RKill

Junkware Removal Tool

Deals

Categories

eLearning

IT Certification Courses

Gear + Gadgets

Security

VPNs

Popular

Best VPNs

How to change IP address

Access the dark web safely

Best VPN for YouTube

Forums
More

Virus Removal Guides
Startup Database
Uninstall Database
Glossary
Send us a Tip!
Welcome Guide

HomeNewsSecurityMacSync malware uses public iCloud calendars to deliver new payloads

MacSync malware uses public iCloud calendars to deliver new payloads

By Bill Toulas

September 24, 2026
04:53 PM
0

A new variant of the MacSync info-stealing malware targeting macOS systems now uses public iCloud calendar events to deliver fresh payloads.
MacSync is a Swift-based malware that emerged in April 2025 and has been observed recently being delivered in ClickFix campaigns disguised as Homebrew and macOS disk space analyzer tools.
Kaspersky researchers say that while earlier versions of the malware were derived from the AMOS stealer family, MacSync evolved and added new capabilities via modules.
Delivery chain
MacSync has been distributed to victims through social engineering, including ClickFix-style attacks, and through software presented as free, cracked, or as new applications.
The researchers note that the threat actor delivered the malware as a fake crypto wallet called Toria, which had a dedicated website and was promoted over social media platforms.
Kaspersky discovered the MacSync campaign that had two delivery methods. In the more complex one, a downloader fetches commands hidden in the description of a public iCloud calendar event, and then downloads the next-stage payload from iCloud.
The downloader feeds the retrieved calendar data to macOS's zsh shell. Most of the calendar text produces errors, but commands placed after the event’s DESCRIPTION: line run and fetch an archive with the malware components.
The archive contains an ‘APP’ bundle that acts as a dropper, leading to more stages that eventually retrieve the MacSync malware.

The latest MacSync infection chainsSource: Kaspersky
New backdoor module
The infostealer module remains largely unchanged, targeting browser history, cookies, and saved credentials, crypto wallet extension and app data, Telegram data, the Keychain file, system and device information, SSH, AWS, Kubernetes, Git, and shell configuration files.

Malware-generated password promptsSource: Kaspersky
The new module observed is an Objective-C backdoor that disguises itself as Finder, the default file manager on macOS. Its installer establishes persistence through a LaunchAgent, .zshrc modifications, and global Git hooks, while terminating macOS notification processes to prevent alerts from reaching the user.
The backdoor can perform the following actions on infected systems:
Run attacker-supplied AppleScript received from its command-and-control server.
Deploy a browser extension or replace an installed Ledger wallet app with versions supplied by the command-and-control (C2) server.
Collect additional system information and files, and upload them to the C2 server.
Check and establish persistence so it starts again after a reboot.
Kaspersky inferred the commands’ purposes from their names and status messages because it did not have the AppleScript code they would execute
The researchers also identified a “mystery” command, live_browser, which downloads and executes a component called sn_relay, whose purpose Kaspersky could not determine.
As MacSync continues to evolve and adopt more evasive and effective distribution chains, macOS users are advised to avoid executing commands they find online
It is also recommended to avoid downloading DMG files from suspicious sites and treat admin password prompts with caution.

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Save your seat

Related Articles:
New Infinity Stealer malware grabs macOS data via ClickFix luresFake LastPass Authenticator GitHub repos push new Rapuncel infostealerNew AmnesiaStealer macOS malware hijacks browser sessions via remote controlFake Roblox Xeno script launcher pushes infostealer, RAT malwareArch Linux disables AUR package adoption to stop malware flood

Backdoor
iCloud
Info Stealer
Information Stealer
macOS
MacSync
Malware

Bill Toulas
Bill Toulas is a tech writer and infosec news reporter with over a decade of experience working on various online publications, covering open-source, Linux, malware, data breach incidents, and hacks.

Previous Article

Post a Comment Community Rules

You need to login in order to post a comment
Not a member yet? Register Now

You may also like:

  Upcoming Webinar

Popular Stories

ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach

Microsoft reminds admins to migrate Entra ID users to passkeys

New Windows Defender zero-day blocks Microsoft antivirus updates

Sponsor Posts

Overdue a password health-check? Audit your Active Directory for free

Daily detection, monthly validation, 12-hour clocks. Are you VDR & VER ready?

Build cyber resilience with Wazuh: The open-source SIEM & XDR for proactive protection

AI is a data-breach time bomb: Read the new report

Automate Onboarding and Access Reviews with No-Code IGA: See how it works

Follow us:

Main Sections

News
Webinars
VPN Buyer Guides
SysAdmin Software Guides
Downloads
Virus Removal Guides
Tutorials
Startup Database
Uninstall Database
Glossary

Community

Forums
Forum Rules
Chat

Useful Resources

Welcome Guide
Sitemap

Company

About BleepingComputer
Contact Us
Send us a Tip!
Advertising
Write for BleepingComputer
Social & Feeds
Changelog

Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure

Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved

Login

Username

Password

Remember Me

Sign in anonymously

Sign in with Twitter

Not a member yet? Register Now


Reporter

Help us understand the problem. What is going on with this comment?

Spam

Abusive or Harmful

Inappropriate content

Strong language

Other

Read our posting guidelinese to learn what content is prohibited.

Submitting...
SUBMIT

A new variant of the MacSync information-stealing malware, which targets macOS systems, has evolved to utilize public iCloud calendar events for the delivery of fresh payloads. Originating in April 2025, MacSync was previously observed in ClickFix campaigns disguised as tools like Homebrew and macOS disk space analyzers. Kaspersky researchers noted that while earlier versions were derived from the AMOS stealer family, MacSync incorporated new capabilities through added modules. The threat actor distributed the malware via social engineering, often using a fake cryptocurrency wallet named Toria promoted across social media.

The delivery mechanism for MacSync employs a multi-stage process. In the more complex method, a downloader retrieves commands concealed within the description fields of public iCloud calendar events. These retrieved commands are then fed into the macOS zsh shell. Although much of the calendar text results in errors, specific commands placed after the DESCRIPTION line execute functions to run and fetch an archive containing the malware components. This archive includes an 'APP' bundle that functions as a dropper, initiating subsequent stages that ultimately retrieve the full MacSync malware.

The infostealer module, which remains largely consistent, is designed to target extensive system and application data, including browser history, cookies, saved credentials, cryptocurrency wallet extensions, Telegram data, the Keychain file, system and device information, SSH, AWS, Kubernetes, Git, and shell configuration files. A newly observed component is an Objective-C backdoor module that attempts to disguise itself as the default macOS file manager, Finder. This backdoor establishes persistence by modifying LaunchAgent settings, altering .zshrc files, and setting global Git hooks, while simultaneously terminating macOS notification processes to prevent user alerts. This backdoor has the capability to execute AppleScript commands received from its command-and-control server, deploy malicious browser extensions or replace installed Ledger wallet applications with versions supplied by the command-and-control server, collect additional system information and files, upload this data to the C2 server, and establish self-restarting persistence after a system reboot. Researchers also identified a command, live_browser, which downloads and executes a component named sn_relay, the function of which remained undetermined. Given the malware's continuous evolution and the adoption of increasingly evasive distribution methods, users are advised to exercise caution by avoiding the execution of commands found online, refraining from downloading DMG files from suspicious sources, and treating prompts for administrative passwords with extreme caution.