MacSync Turns Public iCloud Calendars Into a Malware Delivery Channel
MacSync malware abuses iCloud calendars to deliver macOS payloads via fake apps, stealing credentials, wallets and deploying a Finder backdoor.
Illustrative image generated with AI
A recently observed MacSync campaign is using public iCloud calendar events to distribute instructions and retrieve additional malicious payloads. The technique allows attackers to place part of the delivery chain inside legitimate Apple infrastructure while relying on social engineering to persuade macOS users to begin the infection.
The latest variant also introduces an Objective-C backdoor disguised as Finder. Beyond stealing credentials and application data, the malware can maintain several persistence mechanisms, execute attacker-provided AppleScript, modify cryptocurrency-related software, and suppress system notifications.
Kaspersky’s findings were reported on September 24, 2026. No formal severity score has been assigned, and the exact macOS versions affected have not been disclosed.
Fake applications provide the initial foothold
MacSync is a Swift-based information stealer that first appeared in April 2025. Kaspersky researchers determined that its early versions drew from the AMOS stealer, but subsequent development expanded the malware into a more modular platform.
The operators rely heavily on user deception rather than exploiting a documented macOS vulnerability. MacSync has been distributed through software advertised as free, cracked, or newly released, as well as through ClickFix campaigns impersonating Homebrew and disk-space analysis utilities.
In one campaign, attackers promoted a fake cryptocurrency wallet called Toria through social media. A dedicated website gave the application a more credible appearance and directed prospective victims toward the malicious software.
Kaspersky identified two delivery methods connected to that operation. The more elaborate chain uses a downloader that consults a public iCloud calendar event for instructions before retrieving another payload from iCloud.
This approach shifts part of the attack away from a conventional malware-hosting server. It does not make iCloud or Calendar inherently compromised; the attackers are abusing content hosted through a legitimate public-sharing feature.
Calendar text becomes input for the macOS shell
The distinctive element of the campaign is how the downloader processes the public calendar event.
After retrieving the calendar content, the malware passes it to zsh, the default shell on modern macOS installations. Most of the calendar data produces errors because it is not valid shell syntax. However, commands placed after the event’s DESCRIPTION: field still execute.
In effect, the calendar entry doubles as remotely hosted command material. The surrounding formatting does not need to be interpreted cleanly as long as the strategically positioned shell instructions remain executable.
Those commands retrieve an archive containing an APP bundle dropper. The dropper then begins additional stages that eventually download and run MacSync.
The method gives the operators flexibility to alter downstream instructions without rebuilding every component in the infection chain. It also places the command material in a service that defenders may be less inclined to block broadly because it belongs to Apple’s ecosystem.
The available findings do not identify a software flaw that allows the attack to bypass macOS security by itself. A victim must first be induced to download or execute malicious content, potentially including commands copied from a fraudulent website.
A Finder disguise conceals a persistent backdoor
The newly documented component is an Objective-C backdoor that presents itself as Finder, Apple’s standard file manager. This impersonation is intended to make the process or application appear familiar if a victim notices it.
Its installer establishes persistence through several mechanisms:
- A macOS LaunchAgent
- Modifications to the user’s
.zshrcfile - Global Git hooks
Using multiple persistence points gives the malware additional ways to run again after a reboot or user login. The backdoor can also check whether persistence remains intact and restore it when necessary.
The installer terminates macOS notification processes as well. Suppressing alerts can reduce the chance that users notice security prompts or other visible evidence of malicious activity.
Once active, the backdoor accepts instructions from its command-and-control server. It can execute AppleScript supplied by the operator, collect system information, upload files, and download further components.
Some capabilities directly target cryptocurrency users. The backdoor can install a browser extension or replace an existing Ledger wallet application with a version delivered by the C2 server. That functionality creates a path for manipulating wallet-related activity beyond simply searching for locally stored data.
Kaspersky inferred the likely purpose of several commands from their names and returned status messages because the corresponding AppleScript was unavailable for analysis. Those interpretations therefore do not provide a complete view of every supported operation.
One command, live_browser, downloads and executes a component named sn_relay. Its function remains unknown.
Credentials, wallets, and developer secrets are exposed
MacSync retains the broad collection capabilities expected from an information stealer. Its targets include browser history, cookies, and stored credentials, all of which can support account hijacking or session theft.
The malware also searches for cryptocurrency wallet extensions and application data. Telegram information and the macOS Keychain file are additional collection targets.
Its reach extends into files commonly used by developers, system administrators, and cloud engineers. MacSync looks for:
- SSH configuration and related files
- AWS data
- Kubernetes configuration
- Git configuration
- Shell configuration files
- System and device details
The potential consequences depend on what is stored on the infected Mac. Stolen browser cookies could expose authenticated sessions, while SSH keys or cloud configuration may provide access to remote systems. Wallet data and modified cryptocurrency software create a separate financial risk.
The backdoor also enables continued access after the initial theft. Operators can deliver more payloads, run AppleScript, upload selected files, or repair persistence mechanisms following a reboot.
No quantified impact or formal severity rating has been published. Specific victim counts, targeted countries, file hashes, C2 addresses, and the full set of malicious domains have not been disclosed.
This is a malware campaign, not a CVE-tracked flaw
No CVE identifier is associated with the described activity. The campaign depends on malicious applications, shell execution, and social engineering rather than a disclosed vulnerability in a particular macOS release.
For that reason, there is no corresponding entry or remediation deadline in the US Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog. The absence of a CVE does not reduce the danger, but it changes the defensive response: there is no single operating-system patch identified as fixing the infection route.
The exact macOS versions exposed to MacSync have not been disclosed. The campaign should therefore be treated as potentially relevant to any environment where users can download untrusted DMG files, execute copied terminal commands, or approve unexpected administrator prompts.
Defenders should inspect persistence points and user-driven installs
Kaspersky advises macOS users not to run commands copied from websites or social media instructions. Commands presented as installation steps, security checks, Homebrew fixes, or troubleshooting procedures deserve particular scrutiny when they originate outside a trusted project.
Users should also avoid DMG files from suspicious download sites, especially those advertising cracked applications, unreleased software, cryptocurrency tools, or free versions of commercial products. An unexpected request for an administrator password should be treated as a warning rather than a routine installation step.
For suspected infections, defenders should examine LaunchAgents, .zshrc modifications, and global Git hooks for unauthorized entries. They should also investigate processes masquerading as Finder, unexplained termination of notification services, and the presence or execution of sn_relay.
Cryptocurrency users should verify that their Ledger application and browser extensions came from legitimate distribution channels and have not been replaced. Because MacSync targets the Keychain, browser credentials, cookies, SSH material, and cloud configuration, incident response may require credential rotation and session revocation after the affected system has been isolated and cleaned.
The iCloud calendar technique is only one stage of the operation. Preventing the initial user-driven execution remains the most direct way to stop the chain.
Sources
This article is an original reworking based on the sources below.




