Malware

MacSync Malware Evolves to Use Public iCloud Calendars for Payload Delivery

September 25, 2026 00:00 · 5 min read
MacSync Malware Evolves to Use Public iCloud Calendars for Payload Delivery

MacSync Malware Adopts iCloud Calendar for Stealthy Payload Delivery

A newly discovered variant of the MacSync info-stealing malware targeting macOS systems now leverages public iCloud calendar events to deliver additional payloads, according to research from Kaspersky. First observed in April 2025, MacSync is a Swift-based malware that has evolved from earlier versions derived from the AMOS stealer family, incorporating new modular capabilities to enhance its evasion and functionality.

The malware is primarily distributed through social engineering tactics, including ClickFix-style campaigns that disguise malicious payloads as legitimate tools such as Homebrew utilities or macOS disk space analyzers. In one notable campaign, threat actors distributed MacSync via a fake cryptocurrency wallet named Toria, which was promoted through a dedicated website and social media platforms to lure unsuspecting users.

Infection Chain Exploits Public iCloud Calendar Descriptions

Kaspersky analysts identified two delivery methods for MacSync, with the more sophisticated approach involving a downloader that retrieves hidden commands from the description field of a public iCloud calendar event. Once fetched, the calendar data is passed to the macOS zsh shell for execution. While most of the calendar text generates shell errors, any commands placed after the DESCRIPTION: line are executed, triggering the download of an archive containing the malware components.

This archive includes an ‘APP’ bundle that functions as a dropper, initiating a multi-stage infection process that ultimately leads to the deployment of the core MacSync malware. The use of public iCloud calendars allows attackers to update payloads dynamically without altering the initial downloader, increasing the resilience and flexibility of the attack chain.

Updated Malware Modules Enhance Stealth and Persistence

The infostealer component of MacSync remains consistent with earlier versions, harvesting sensitive data such as browser history, cookies, saved credentials, cryptocurrency wallet data (including extensions and app files), Telegram messages, Keychain access, system and device information, SSH configurations, AWS and Kubernetes credentials, Git settings, and shell configuration files.

In addition to the infostealer, researchers uncovered a new Objective-C-based backdoor module designed to mimic Finder, macOS’s default file manager, to avoid suspicion. This module establishes persistence through multiple mechanisms: creating a LaunchAgent, modifying the user’s .zshrc file, installing global Git hooks, and terminating macOS notification processes to suppress security alerts that might otherwise warn the user.

The backdoor is capable of executing attacker-supplied AppleScript received from its command-and-control (C2) server, deploying malicious browser extensions, replacing legitimate Ledger wallet applications with malicious versions supplied by the C2, gathering additional system data for exfiltration, and ensuring it reactivates after system reboot by verifying and reinforcing its persistence mechanisms.

Unclear Functionality in ‘live_browser’ Command Raises Concerns

Kaspersky researchers noted that while they could infer the purpose of most backdoor commands from their names and status messages, they were unable to analyze the underlying AppleScript code due to obfuscation or encryption. One particular command, labeled live_browser, downloads and executes a component named sn_relay, whose function remains undetermined. This uncertainty highlights the evolving complexity of MacSync’s modular architecture and the challenges in fully mapping its capabilities.

As MacSync continues to refine its distribution techniques and adopt more evasive execution chains, security experts advise macOS users to exercise caution when encountering online instructions involving terminal commands, avoid downloading DMG files from unverified or suspicious websites, and treat unexpected administrative password prompts with skepticism, as these are common indicators of malware activity.


Source: BleepingComputer

Source: BleepingComputer

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free