Back to Feed
MalwareSep 24, 2026

MacSync malware uses public iCloud calendars to deliver new payloads

MacSync malware uses public iCloud calendars to deliver new macOS payloads.

Summary

A new variant of the MacSync info-stealing malware for macOS has been discovered using public iCloud calendar events to deliver its payloads. This malware, which emerged in April 2025, has been observed in ClickFix campaigns and disguised as legitimate tools. It has evolved with new modules, including a backdoor that can execute attacker-supplied scripts and deploy malicious browser extensions.

Full text

MacSync malware uses public iCloud calendars to deliver new payloads By Bill Toulas September 24, 2026 04:53 PM 0 A new variant of the MacSync info-stealing malware targeting macOS systems now uses public iCloud calendar events to deliver fresh payloads. MacSync is a Swift-based malware that emerged in April 2025 and has been observed recently being delivered in ClickFix campaigns disguised as Homebrew and macOS disk space analyzer tools. Kaspersky researchers say that while earlier versions of the malware were derived from the AMOS stealer family, MacSync evolved and added new capabilities via modules. Delivery chain MacSync has been distributed to victims through social engineering, including ClickFix-style attacks, and through software presented as free, cracked, or as new applications. The researchers note that the threat actor delivered the malware as a fake crypto wallet called Toria, which had a dedicated website and was promoted over social media platforms. Kaspersky discovered the MacSync campaign that had two delivery methods. In the more complex one, a downloader fetches commands hidden in the description of a public iCloud calendar event, and then downloads the next-stage payload from iCloud. The downloader feeds the retrieved calendar data to macOS's zsh shell. Most of the calendar text produces errors, but commands placed after the event’s DESCRIPTION: line run and fetch an archive with the malware components. The archive contains an ‘APP’ bundle that acts as a dropper, leading to more stages that eventually retrieve the MacSync malware. The latest MacSync infection chainsSource: Kaspersky New backdoor module The infostealer module remains largely unchanged, targeting browser history, cookies, and saved credentials, crypto wallet extension and app data, Telegram data, the Keychain file, system and device information, SSH, AWS, Kubernetes, Git, and shell configuration files. Malware-generated password promptsSource: Kaspersky The new module observed is an Objective-C backdoor that disguises itself as Finder, the default file manager on macOS. Its installer establishes persistence through a LaunchAgent, .zshrc modifications, and global Git hooks, while terminating macOS notification processes to prevent alerts from reaching the user. The backdoor can perform the following actions on infected systems: Run attacker-supplied AppleScript received from its command-and-control server. Deploy a browser extension or replace an installed Ledger wallet app with versions supplied by the command-and-control (C2) server. Collect additional system information and files, and upload them to the C2 server. Check and establish persistence so it starts again after a reboot. Kaspersky inferred the commands’ purposes from their names and status messages because it did not have the AppleScript code they would execute The researchers also identified a “mystery” command, live_browser, which downloads and executes a component called sn_relay, whose purpose Kaspersky could not determine. As MacSync continues to evolve and adopt more evasive and effective distribution chains, macOS users are advised to avoid executing commands they find online It is also recommended to avoid downloading DMG files from suspicious sites and treat admin password prompts with caution. Build your security blueprint for AI-powered attacks Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Save your seat Related Articles: New Infinity Stealer malware grabs macOS data via ClickFix luresFake LastPass Authenticator GitHub repos push new Rapuncel infostealerNew AmnesiaStealer macOS malware hijacks browser sessions via remote controlFake Roblox Xeno script launcher pushes infostealer, RAT malwareArch Linux disables AUR package adoption to stop malware flood

Entities

iCloud Calendar (product)