MacSync macOS Malware Abuses Public iCloud Calendars to Deliver New Payload
A new variant of the MacSync information-stealing malware targeting macOS systems uses publicly available iCloud Calendar events to deliver a new payload.
MacSync is a Swift-based malware family that first appeared in April 2025. It has recently been distributed through ClickFix campaigns disguised as Homebrew and macOS disk-space analysis tools.
According to researchers at Kaspersky, early versions of MacSync originated from the AMOS stealer family. The malware has since evolved by adding new functionality through separate modules.
MacSync malware delivery chain
MacSync is distributed through social engineering, including ClickFix-style attacks and software promoted as free, cracked, or newly released applications.
Researchers said the attackers operated a dedicated website and distributed the malware as a fake cryptocurrency wallet called Toria. The wallet was promoted on social media platforms.
Kaspersky identified a MacSync campaign using two delivery methods. In the more complex infection chain, a downloader retrieves commands hidden in the description of a public iCloud Calendar event and downloads the next-stage payload from iCloud.
The downloader feeds the retrieved calendar data to the macOS zsh shell. Most of the calendar text produces an error, but the command placed after the DESCRIPTION: line is executed to retrieve an archive containing the malware component.
The archive contains an APP bundle that acts as a dropper. It launches additional stages that eventually retrieve the MacSync malware.

Source: Kaspersky
MacSync adds a new backdoor module
The MacSync infostealer module remains largely unchanged. It can target browser history, cookies, saved credentials, cryptocurrency wallet extensions, application data, Telegram data, keychain files, system and device information, SSH data, AWS and Kubernetes files, Git data, and shell configuration files.

Source: Kaspersky
Kaspersky also observed a new module, described in its analysis of the latest MacSync version. The Objective-C backdoor masquerades as Finder, the default file manager in macOS.
Its installer establishes persistence through a LaunchAgent, changes to .zshrc, and global Git hooks. It also terminates the macOS notification process to prevent alerts from reaching users.
The backdoor can perform the following actions on an infected system:
- Execute AppleScript received through an attacker-controlled command from a command-and-control (C2) server.
- Deploy a browser extension or replace the installed Ledger wallet application with a version provided by the C2 server.
- Collect additional system information and files and upload them to the C2 server.
- Check and establish persistence so that it starts again after a reboot.
Kaspersky did not have the AppleScript code associated with the command, so researchers inferred its purpose from the command name and status message.
Researchers also identified two additional commands: live browser, which downloads and runs a component, and sn_relay, whose purpose Kaspersky was unable to determine.
How to protect your Mac from MacSync
As MacSync continues to evolve and use more evasive distribution methods, macOS users should avoid running commands they find online.
Users should also avoid downloading DMG files from questionable websites and be wary of unexpected administrator password prompts.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a 2-hour digital summit about what will change with AI speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



