A sophisticated and evolving strain of MacSync malware, designed to pilfer sensitive information from macOS systems, has adopted a novel and stealthy distribution method: public iCloud calendar events. This development marks a significant escalation in the threat actor’s tactics, moving beyond traditional downloaders and social engineering to exploit the seemingly innocuous functionality of cloud-based calendaring services. Researchers at Kaspersky have detailed this new attack vector, highlighting the malware’s adaptability and the increasing sophistication of threats targeting the Apple ecosystem.
Background and Evolution of MacSync
MacSync, first identified in April 2025, is a malware family written in Swift, a popular programming language for Apple’s platforms. Initially, it was recognized as a variant of the AMOS stealer, a known family of information-stealing malware. However, recent observations reveal a significant evolution, with MacSync developing modular capabilities that allow for expanded functionality and a more potent threat profile. This modular architecture enables the malware to be updated and adapted by its creators, making it a persistent and dynamic adversary.
The malware has been disseminated through various deceptive practices. Earlier campaigns, as reported by BleepingComputer, involved "ClickFix" operations, where MacSync was disguised as legitimate software such as Homebrew, a package manager for macOS, or disk space analyzer tools. This social engineering approach relies on users’ trust in seemingly helpful utilities to gain initial access to their systems. Furthermore, threat actors have employed more elaborate schemes, such as the promotion of a fake cryptocurrency wallet named "Toria," complete with a dedicated website and social media marketing, to lure unsuspecting users into downloading the malicious software.
The Innovative iCloud Calendar Delivery Chain
The most striking innovation in the latest MacSync campaign lies in its payload delivery mechanism. Kaspersky’s analysis has uncovered a two-pronged approach, with a particularly intricate method involving public iCloud calendars. In this advanced scenario, the initial downloader component of the malware operates with a degree of subterfuge. It retrieves commands that are not embedded in typical malicious code but are instead hidden within the description fields of public iCloud calendar events.

These calendar events, seemingly innocuous calendar entries, are meticulously crafted to contain the necessary instructions for the downloader. When the malware executes on an infected system, it interacts with macOS’s built-in zsh shell. The bulk of the text within the calendar description typically results in harmless errors, a clever tactic to obscure the actual commands. However, specific commands, strategically placed after a "DESCRIPTION:" line, are parsed and executed. These commands then instruct the downloader to fetch the next-stage payload, which is hosted on iCloud itself.
The retrieved calendar data, once processed by the zsh shell, triggers the download of an archive file. This archive typically contains an ".APP" bundle, which functions as a dropper. This dropper is designed to execute a series of subsequent stages, each designed to further obfuscate the malware’s true nature and ultimately deliver the core MacSync infostealer and its associated modules. This multi-stage approach is a common tactic in advanced malware to evade detection by security software, which may only flag the initial dropper and not the final malicious payload.
Timeline of Detection and Analysis
The emergence of MacSync was first noted in April 2025. Initial reports focused on its capabilities as an information stealer and its distribution through social engineering tactics. The ClickFix campaigns, masquerading as system utilities, were a significant early indicator of the malware’s presence.
By late 2025, Kaspersky researchers began to observe the evolution of MacSync, noting its increasing modularity and the addition of new functionalities. The discovery of the iCloud calendar-based delivery chain represents a more recent development, detailed in Kaspersky’s security advisories and research publications during September 2026. This timeline underscores the rapid pace at which MacSync is being developed and deployed, presenting an ongoing challenge for cybersecurity professionals.
The Evolved Infostealer Module and New Backdoor Capabilities
The core infostealer module of MacSync remains a formidable threat, largely unchanged in its primary function. It is designed to exfiltrate a wide array of sensitive data from infected macOS systems. This includes:

- Browser Data: History, cookies, and saved login credentials from various web browsers.
- Cryptocurrency Wallets: Data associated with cryptocurrency wallet extensions and standalone applications, posing a direct financial threat to users.
- Communication Data: Information stored within Telegram, a popular messaging application.
- System Credentials: The highly sensitive Keychain file, which stores user passwords and other authentication tokens.
- System and Device Information: Comprehensive details about the infected hardware and software configuration.
- Development and Cloud Credentials: Configuration files for SSH, AWS (Amazon Web Services), Kubernetes, Git, and shell environments, which can grant attackers access to critical infrastructure and code repositories.
Beyond the core infostealer, the latest MacSync variant incorporates a new and significant module: an Objective-C backdoor. This backdoor is particularly insidious as it disguises itself as "Finder," the default file management application on macOS. This mimicry aims to blend in with legitimate system processes, making it harder for users and security tools to identify.
The installer for this backdoor is engineered for persistence. It establishes its presence on the system through several mechanisms:
- LaunchAgents: These are system daemons that can launch applications or scripts automatically at user login or system startup, ensuring the backdoor remains active.
- .zshrc Modifications: The backdoor alters the
.zshrcfile, a configuration script for the zsh shell, to execute malicious code whenever a new terminal session is opened. - Global Git Hooks: By manipulating global Git hooks, the backdoor can execute commands in response to Git operations, potentially compromising development workflows.
Furthermore, the backdoor actively attempts to suppress user awareness by terminating macOS notification processes. This prevents users from receiving alerts that might otherwise indicate suspicious activity on their systems.
The backdoor module is equipped with a range of functionalities, allowing the threat actor to exert significant control over infected machines. While Kaspersky researchers could not access the AppleScript code executed by these commands, they inferred their purposes from their names and status messages. These inferred capabilities include:
- File Management: Commands likely allow for the listing, reading, writing, and deletion of files on the compromised system, enabling data exfiltration or manipulation.
- Process Control: The ability to list and terminate processes suggests the backdoor can monitor system activity and eliminate competing malware or security software.
- System Information Gathering: Commands to gather system information indicate a desire to map the compromised environment and identify further targets or vulnerabilities.
- Network Operations: Potential for network-related commands suggests the backdoor might be capable of establishing further connections, downloading additional tools, or facilitating lateral movement within a network.
A particularly intriguing discovery is a command labeled "mystery" by researchers: live_browser. This command is designed to download and execute a component named sn_relay. The exact purpose of sn_relay remains undetermined by Kaspersky, adding another layer of unknown threat to the MacSync arsenal. This unknown component could be designed for advanced reconnaissance, data exfiltration, or even to serve as a pivot point for further attacks.
Implications for macOS Users and the Cybersecurity Landscape
The evolution of MacSync, particularly its adoption of iCloud calendar events for payload delivery, carries significant implications for macOS users and the broader cybersecurity community.

Firstly, it highlights a shift towards exploiting cloud services in novel ways. Attackers are no longer solely relying on direct downloads or compromised websites. The ability to embed commands and payloads within widely used cloud platforms like iCloud demonstrates a creative and potentially more effective method of evading traditional security defenses. Cloud security measures, often focused on data access and sharing, may not be adequately equipped to detect malicious code embedded within calendar event descriptions.
Secondly, the modular nature of MacSync and the addition of a stealthy backdoor underscore the increasing sophistication of macOS malware. What may have started as a relatively straightforward information stealer has evolved into a multi-functional threat capable of persistent access, data theft, and potentially remote control. This necessitates a proactive and adaptive approach to macOS security.
Thirdly, the social engineering tactics employed, from fake cryptocurrency wallets to disguised system utilities, continue to be a primary vector for initial compromise. This emphasizes the enduring importance of user education and awareness in cybersecurity. Users must be vigilant about the software they download, the websites they visit, and the requests for administrative privileges they encounter.
Recommendations for Mitigation and Defense
In light of these evolving threats, cybersecurity experts offer several crucial recommendations for macOS users:
- Exercise Extreme Caution with Online Commands: Users should avoid executing commands found online, particularly those from untrusted sources or forums. These commands, even if seemingly innocuous, can be part of a larger malicious script.
- Be Wary of Downloaded Files: Avoid downloading DMG files or other software installers from suspicious or unofficial websites. Always verify the source of any software before installation.
- Treat Administrative Password Prompts with Skepticism: Be highly cautious when prompted for administrative passwords. Legitimate software installations typically require this, but malware often attempts to trick users into granting elevated privileges. Investigate the legitimacy of the prompt before proceeding.
- Maintain Updated Security Software: Ensure that anti-malware and anti-virus software for macOS is kept up-to-date. These tools can help detect and remove known threats.
- Regularly Review iCloud Settings: While not directly preventing malware execution, users can review their iCloud sharing settings to ensure they are not inadvertently making calendars public that could be exploited.
- Enable Two-Factor Authentication: For iCloud accounts, enabling two-factor authentication adds a critical layer of security, making it harder for attackers to gain unauthorized access to account information, including calendars.
The continuous evolution of MacSync serves as a stark reminder that the cybersecurity landscape is in constant flux. As threat actors innovate and adapt, so too must the defenses employed by individuals and organizations to protect their digital assets. The ability of MacSync to leverage public iCloud calendars for payload delivery is a significant development that warrants close attention from security researchers and proactive vigilance from all macOS users.







