Skip to content
Tech News
← Back to articles

MacSync macOS malware now abuses public iCloud calendars for payload delivery

read original get Malwarebytes Premium for Mac → more articles
GoKawiil Brief

Kaspersky researchers report a new variant of the MacSync info-stealing malware that hides commands inside public iCloud calendar event descriptions to fetch additional payloads onto infected Macs. The malware, which evolved from the AMOS stealer family, has been spread via ClickFix-style social engineering, fake Homebrew and disk-analyzer tools, and a bogus crypto wallet app called Toria. A newly discovered Objective-C backdoor module disguises itself as Finder to maintain persistence.

Why It Matters

GoKawiil's interpretation of the reporting above, not reported fact.

Using a trusted, legitimate service like iCloud calendars to smuggle commands could help attackers evade detection tools that focus on suspicious domains or servers, since the traffic blends in with normal Apple ecosystem activity. The addition of a backdoor module alongside the existing data-theft functions suggests the group behind MacSync may be moving toward longer-term access on compromised machines rather than one-off credential theft. This case also underscores how macOS threats are increasingly borrowing techniques long used against Windows users, such as fake installers and cracked software lures.

Key Takeaways
Worth a Look

Malwarebytes Premium for Mac — With MacSync and similar info-stealers increasingly targeting macOS through fake apps and cracked software, having dedicated Mac security software that watches for malicious downloaders and suspicious shell activity is a smart layer of defense. Malwarebytes for Mac specifically targets Mac-focused threats like adware, trojans, and info-stealers that traditional antivirus can miss.

See Malwarebytes Premium for Mac on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

Source: bleepingcomputer.com, 2026-09-24

Published there as: “MacSync malware uses public iCloud calendars to deliver new payloads”

Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.