Updated
Updated · Fox News · Oct 4
MacSync Hides Commands in iCloud Calendar Events to Download More Malware
Updated
Updated · Fox News · Oct 4

MacSync Hides Commands in iCloud Calendar Events to Download More Malware

1 articles · Updated · Fox News · Oct 4

Summary

  • Kaspersky found a September 2026 MacSync variant that pulls commands from a public iCloud calendar event, then uses them to fetch another malicious app from iCloud.
  • The calendar event does not infect Macs by itself; the attack starts after a user runs a malicious app, letting attackers hide later-stage activity behind trusted Apple infrastructure.
  • MacSync is an information stealer that can grab browser passwords, cookies, Keychain data, Telegram information, crypto wallet files and developer credentials including SSH, AWS, Kubernetes and Git configurations.
  • A separate Objective-C backdoor masquerades as Finder, persists through LaunchAgent, .zshrc and Git-hook changes, and can suppress some macOS notifications while taking remote commands.
  • Researchers also traced MacSync to a fake Toria crypto wallet promoted on X and Telegram, underscoring Apple's warning to avoid untrusted downloads, pasted Terminal commands and outdated macOS systems.

Insights

How are cybercriminals weaponizing your trusted iCloud Calendar to silently deploy the MacSync infostealer?
What is the true purpose of the mysterious sn_relay component secretly downloaded onto infected Mac devices?
If Apple's security is so robust, why do polished fake apps still effortlessly bypass Gatekeeper?