MacSync malware uses public iCloud calendars to deliver new payloads
Recorded: Sept. 24, 2026, 9:10 p.m.
| Original | Summarized |
MacSync malware uses public iCloud calendars to deliver new payloads News Featured ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach New Windows Defender zero-day blocks Microsoft antivirus updates EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts Check Point warns of Management Server zero-day exploited in attacks MacSync malware uses public iCloud calendars to deliver new payloads New Carbonato malware uses AI agents to hijack exposed Docker hosts Drop monthly subscriptions with a $79.99 lifetime PDF editor for Mac Exposed GitLab project email addresses let attackers push code Tutorials Latest How to access the Dark Web using the Tor Browser How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11 How to use the Windows Registry Editor How to backup and restore the Windows Registry How to start Windows in Safe Mode How to remove a Trojan, Virus, Worm, or other Malware How to show hidden files in Windows 7 How to see hidden files in Windows Webinars Latest Qualys BrowserCheck STOPDecrypter AuroraDecrypter FilesLockerDecrypter AdwCleaner ComboFix RKill Junkware Removal Tool Deals Categories eLearning IT Certification Courses Gear + Gadgets Security VPNs Popular Best VPNs How to change IP address Access the dark web safely Best VPN for YouTube Forums Virus Removal Guides HomeNewsSecurityMacSync malware uses public iCloud calendars to deliver new payloads MacSync malware uses public iCloud calendars to deliver new payloads By Bill Toulas September 24, 2026 A new variant of the MacSync info-stealing malware targeting macOS systems now uses public iCloud calendar events to deliver fresh payloads. The latest MacSync infection chainsSource: Kaspersky Malware-generated password promptsSource: Kaspersky Build your security blueprint for AI-powered attacks Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Related Articles: Backdoor Bill Toulas Previous Article Post a Comment Community Rules You need to login in order to post a comment You may also like: Upcoming Webinar Popular Stories ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach Microsoft reminds admins to migrate Entra ID users to passkeys New Windows Defender zero-day blocks Microsoft antivirus updates Sponsor Posts Overdue a password health-check? Audit your Active Directory for free Daily detection, monthly validation, 12-hour clocks. Are you VDR & VER ready? Build cyber resilience with Wazuh: The open-source SIEM & XDR for proactive protection AI is a data-breach time bomb: Read the new report Automate Onboarding and Access Reviews with No-Code IGA: See how it works Follow us: Main Sections News Community Forums Useful Resources Welcome Guide Company About BleepingComputer Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved Login Username Password Remember Me Sign in anonymously Sign in with Twitter Not a member yet? Register Now Help us understand the problem. What is going on with this comment? Spam Abusive or Harmful Inappropriate content Strong language Other Read our posting guidelinese to learn what content is prohibited. Submitting... |
A new variant of the MacSync information-stealing malware, which targets macOS systems, has evolved to utilize public iCloud calendar events for the delivery of fresh payloads. Originating in April 2025, MacSync was previously observed in ClickFix campaigns disguised as tools like Homebrew and macOS disk space analyzers. Kaspersky researchers noted that while earlier versions were derived from the AMOS stealer family, MacSync incorporated new capabilities through added modules. The threat actor distributed the malware via social engineering, often using a fake cryptocurrency wallet named Toria promoted across social media. The delivery mechanism for MacSync employs a multi-stage process. In the more complex method, a downloader retrieves commands concealed within the description fields of public iCloud calendar events. These retrieved commands are then fed into the macOS zsh shell. Although much of the calendar text results in errors, specific commands placed after the DESCRIPTION line execute functions to run and fetch an archive containing the malware components. This archive includes an 'APP' bundle that functions as a dropper, initiating subsequent stages that ultimately retrieve the full MacSync malware. The infostealer module, which remains largely consistent, is designed to target extensive system and application data, including browser history, cookies, saved credentials, cryptocurrency wallet extensions, Telegram data, the Keychain file, system and device information, SSH, AWS, Kubernetes, Git, and shell configuration files. A newly observed component is an Objective-C backdoor module that attempts to disguise itself as the default macOS file manager, Finder. This backdoor establishes persistence by modifying LaunchAgent settings, altering .zshrc files, and setting global Git hooks, while simultaneously terminating macOS notification processes to prevent user alerts. This backdoor has the capability to execute AppleScript commands received from its command-and-control server, deploy malicious browser extensions or replace installed Ledger wallet applications with versions supplied by the command-and-control server, collect additional system information and files, upload this data to the C2 server, and establish self-restarting persistence after a system reboot. Researchers also identified a command, live_browser, which downloads and executes a component named sn_relay, the function of which remained undetermined. Given the malware's continuous evolution and the adoption of increasingly evasive distribution methods, users are advised to exercise caution by avoiding the execution of commands found online, refraining from downloading DMG files from suspicious sources, and treating prompts for administrative passwords with extreme caution. |