MacSync malware conceals commands in iCloud calendar to steal data from Macs

MacSync malware conceals commands in iCloud calendar to steal data from Macs

You likely use your calendar for scheduling appointments, remembering birthdays, or for those reminders you sometimes just snooze. It appears hackers have discovered another way to utilize these features. Security researchers have identified a new variant of MacSync malware capable of exploiting public iCloud calendar events as part of its infection strategy. Inside the calendar data, there are hidden commands that enable the download of further malware onto a Mac.

It’s important to note that simply receiving a calendar invitation won’t infect your computer. The initial infection typically happens when someone downloads and runs a malicious application. Nevertheless, this iCloud tactic illustrates how attackers can conceal aspects of their assault behind trusted services. Once MacSync infiltrates a system, its reach extends far beyond just the calendar. Let’s take a moment to unpack how MacSync functions, what information it can compromise, and how to safeguard your Mac.

What is MacSync malware?

MacSync is a type of malware aimed at stealing information from macOS. Earlier versions showed similarities to a known malware called Atomic macOS Stealer, or AMOS. Researchers mention that MacSync has since evolved its capabilities. Kaspersky reports that it first surfaced on the dark web in 2025, initially named Mac.c before being rebranded as MacSync. The latest iteration was detected in the wild in September 2026.

This malware operates under a malware-as-a-service framework, allowing different criminals to deploy it while choosing their specific methods of installation. Prior instances have involved social engineering tactics or deceptive messages persuading users to copy and execute a command. It has also been disguised as free software or cracked applications. There have been similar ploys seen before. In one case, misleading CAPTCHA tasks convinced individuals to input commands into Terminal, leading them to install information-stealing malware.

How hackers can abuse iCloud calendars

This new version takes a particularly devious turn. Kaspersky discovered a chain of infection where a downloader was linked to a public iCloud calendar. Instead of using it to schedule events, attackers incorporated harmful commands within the event description. The malware processes this calendar information through the Zsh command-line shell on the Mac.

Most of the calendar data produces errors as the Mac fails to recognize standard calendar details as commands. However, when it encounters the malicious instructions following the event’s description, those commands can execute and ultimately download compressed files from iCloud that contain more malicious software. This method showcases the calendar’s role as a concealer for the instructions needed to launch the attack. It’s essential to understand that the attacker still needs to get the malware running on the Mac first, but utilizing trusted Apple infrastructure can mask the nefarious activity. Kaspersky also mentions that some samples pointed to a public iCloud calendar while others connected to servers controlled by the attackers.

A fake crypto wallet helped spread MacSync

Researchers have also observed attackers masquerading MacSync as a phony cryptocurrency wallet named Toria. The criminals didn’t just create a download page for it; they also developed a standalone website and promoted it through social media platforms. This serves as a stark reminder that a polished website or active social media presence doesn’t necessarily validate the trustworthiness of software. Crypto owners are particularly enticing targets, as stealing wallet credentials or browser extension data can swiftly lead to lost funds. But even if you don’t own cryptocurrency, there are still things MacSync seeks to exploit.

What MacSync can steal from your Mac

Once it’s on your system, MacSync’s information-stealing module rummages through a plethora of sensitive data. It can capture browser histories, cookies, saved logins, and passwords. It also targets crypto wallet extension data, cryptocurrency wallet apps, and Telegram details.

Moreover, MacSync can collect the user’s login details as well as Keychain files. It gathers system specifics such as installed applications, active processes, hardware information, and device models. Developers and more tech-savvy users might face additional risks since the malware can scan configuration files for SSH, ZSH, AWS, Kubernetes, and Git. It also has the ability to sift through Zsh and Bash command histories. Essentially, if malware gains access to saved passwords or browser data, it opens up another avenue for attackers to infiltrate your online accounts.

The new MacSync backdoor raises the stakes

Kaspersky has identified a distinct backdoor component crafted in Objective-C, which masquerades as the Finder application in macOS. This component employs various methods to maintain its presence even after a Mac reboot. Some techniques involve creating a LaunchAgent, altering the .zshrc configuration file, and changing global Git hooks. It can disrupt several macOS notification processes, thereby preventing system alerts regarding the new LaunchAgent. Once in place, attackers can issue instructions to the compromised device.

Researchers have discovered commands meant to deploy a browser extension, swap an existing Ledger wallet app, and collect further system data or files. Most of these commands execute AppleScript sent from the attacker’s command-and-control server. Kaspersky has been able to infer the purpose of some commands from their names and the notifications they produce, yet they haven’t had access to the actual AppleScript payloads. This missing information is significant; it means while researchers grasp what the backdoor likely intends to do, they may not capture the full spectrum of server-directed scripts.

One MacSync command remains a mystery

Among the commands discovered, one called live_browser downloads and executes a component referred to as sn_relay. Kaspersky has stated that the specific details and function of this component are still unclear. Based on the command’s title and the server messages, researchers believe it might be intended for a man-in-the-middle attack against browser traffic, but confirmation of this remains pending. This uncertainty illustrates how malware research can evolve as more samples are examined.

Why Mac users keep getting tricked

Even though Macs come with built-in security features, many recent attacks aim to convince users to circumvent these protections themselves. ClickFix tactics serve as an ideal example; a website may announce a problem and provide a command that ostensibly resolves the issue. Unfortunately, this can lead you to inadvertently run malware. Previous reports have highlighted Shamos malware, another Mac threat that relied on false troubleshooting to coax users into executing commands in Terminal. The same fundamental lesson persists: always be skeptical of websites requesting you to open Terminal, input commands, or provide your Mac administrator password for unfamiliar software installations.

Mac malware increasingly targets familiar tools

MacSync fits a growing pattern where attackers disguise harmful software as useful tools or familiar applications. In this instance, researchers identified one infection path utilizing Apple’s iCloud infrastructure to spread additional malware. Opening iCloud Calendar itself won’t put your Mac at risk, but it underscores the need for vigilance early in the attack process. Always be wary when unknown applications request your administrator password or when websites ask you to run commands in Terminal.

Apple says macOS has built-in protections against these attacks

Apple claims that macOS is equipped with several layers designed to thwart malicious software from executing, including Gatekeeper, XProtect, and a notarization system for software downloads outside the Mac App Store. They advise using the Mac App Store as the safest route for software acquisition. For applications sourced elsewhere, macOS employs protections such as notarization and XProtect to identify and obstruct malicious software.

On macOS 26.4 and later versions, protections have been enhanced specifically against attacks that try to trick users into pasting commands in Terminal. The system can now display warnings when pasting commands from typical attack vectors like web browsers or messaging applications. Apple indicates that XProtect can inspect activities that arise from these pasted commands, including in third-party terminal applications, checking related network actions against their Safe Browsing Service to block techniques associated with known malware.

Additionally, macOS 26.4 and later support scanning AppleScript and JavaScript for Automation scripts with XProtect. If a script matches recognized malicious signatures, macOS can block it and notify the user. Furthermore, Safari includes more protective measures, such as alerts for suspected phishing websites and blocking harmful domains tied to threats.

Apple also emphasizes the role of social engineering in these attacks. Scammers may attempt to persuade users to download software or insert malicious commands. They recommend only downloading software from trusted sources and keeping macOS consistently up to date with the latest software and security updates.

8 ways to protect your Mac from MacSync malware

MacSync caters heavily to obtaining a user’s cooperation by running a malicious application at the outset of the attack, which presents several opportunities to intervene.

1) Avoid copying Terminal commands from websites

Reliable websites seldom require you to copy obscure commands into Terminal to demonstrate that you’re human, fix a browser issue, or finish a download. Apple indicates that macOS 26.4 and later can alert users when commands copied from various sources are pasted into Terminal. XProtect can also thwart actions linked to known malicious commands.

2) Download apps from trusted sources

Whenever possible, opt to acquire software through the Mac App Store or directly from the developer’s legitimate site. Apple endorses the Mac App Store as the most reliable venue for obtaining software. For third-party applications, be extra cautious about cracked software, free versions of paid apps, and unfamiliar software advertised through social media.

3) Treat administrator password requests seriously

MacSync’s infostealer can disguise itself to make legitimate-looking requests for administrator passwords. If an unfamiliar app prompts for your password unexpectedly, pause and verify why it’s asking before providing any information.

4) Use strong antivirus protection

Robust antivirus software can assist in identifying dangerous downloads and known malware before it compromises your system, providing an additional safety layer when faced with convincing scams.

5) Keep macOS updated

Regularly install macOS updates provided by Apple. Updates patch security vulnerabilities and improve built-in defenses against threats.

6) Check your browser extensions

Remove extensions that you no longer access and scrutinize any unfamiliar ones. MacSync’s backdoor includes commands aimed at deploying browser extensions from the attacker’s servers.

  • Safari: Open Safari, click on Safari in the menu bar, go to Settings, and review Extensions on the left. Uncheck to disable or uninstall them.
  • Google Chrome: Navigate to Chrome, select the three dots in the upper-right corner, go to Extensions, and review suspicious items; disable or remove them as needed.
  • Microsoft Edge: Open Edge, click Extensions next to the address bar, and manage them. Do not hesitate to remove anything you do not recognize.

7) Protect important accounts with 2FA

Enable two-factor authentication wherever it’s an option. If malware compromises your password, this additional verification makes unauthorized account access significantly tougher.

8) Change passwords if you suspect an infection

Begin with your email and financial accounts. If feasible, use a separate trusted device for this. Opt for robust, unique passwords using a password manager, and review active sessions to log out any unfamiliar devices.

Kurt’s key takeaways

MacSync serves as an excellent case of how attackers can camouflage harmful components within familiar pathways of your Mac. An iCloud calendar, Finder, or a common password prompt can all obscure something hazardous as usual. This particular attack still relies on you to initiate malicious software, which gives you a chance to halt it early. If a website instructs you to paste something into Terminal or if an unknown app suddenly requests your administrator password, take a moment to consider why. Those brief moments of skepticism could help you avoid impending risks to your passwords, private information, and access to your accounts.

Do you find seeing an iCloud address or another recognizable Apple service makes you more likely to trust a download, or are you inherently suspicious when a website instructs you to execute commands on your Mac? Feel free to share your thoughts.

Facebook
Twitter
LinkedIn
Reddit
Telegram
WhatsApp

Related News