A fresh variant of the MacSync malware iCloud calendar technique has surfaced, with the Swift-based infostealer now hiding attacker commands inside publicly accessible iCloud calendar event descriptions to pull down next-stage payloads. Kaspersky researchers uncovered the campaign, detailing a malware family that has grown considerably more capable since it first emerged as a variant of the AMOS stealer family in April 2025.
How the MacSync iCloud Calendar Delivery Chain Works
The more complex of the two delivery methods Kaspersky identified involves a downloader that retrieves commands hidden in the description field of a public iCloud calendar event. Those commands are passed directly to macOS’s zsh shell. Most of the calendar text produces errors and goes nowhere, but instructions placed after the event’s DESCRIPTION: line execute cleanly, fetching an archive that contains the next-stage components.
That downloaded archive holds an ‘APP’ bundle acting as a dropper. According to Securelist, the malicious payload inside the dropper is a zlib-compressed executable encrypted with AES in CBC mode, a layer of obfuscation that makes static analysis considerably more awkward. From there, further stages eventually retrieve the MacSync malware itself.
The simpler delivery route leans on social engineering, including ClickFix-style attacks and software presented as free, cracked, or new applications. Kaspersky notes the threat actor distributed MacSync disguised as a fake crypto wallet called Toria, complete with a dedicated website and social media promotion. Other lures have included fake Homebrew installers and macOS disk space analyser tools.
A New Backdoor Module Disguised as Finder
The infostealer module itself remains largely unchanged. It targets browser history, cookies, and saved credentials, along with crypto wallet extension and app data, Telegram data, the Keychain file, system information, SSH, AWS, Kubernetes, Git, and shell configuration files. The expansion comes from a new Objective-C backdoor that disguises itself as Finder, macOS’s default file manager.
The backdoor’s installer establishes persistence through a LaunchAgent, .zshrc modifications, and global Git hooks. It also terminates macOS notification processes, which prevents alerts from reaching the user while it operates. Once in place, the backdoor can run attacker-supplied AppleScript received from its command-and-control (C2) server, deploy or replace browser extensions (including swapping out a legitimate Ledger wallet app for an attacker-controlled version), collect additional files and upload them to the C2 server, and re-establish persistence after a reboot.
Kaspersky noted a ‘mystery’ command, live_browser, which downloads and executes a component called sn_relay, the purpose of which Kaspersky could not determine. The researchers inferred the purposes of other commands from their names and status messages, since the actual AppleScript code those commands would execute was not available to them.
MacSync’s Evolving Techniques
Two details from Help Net Security illustrate how quickly MacSync has matured. First, the new version has moved away from AppleScripts and now uses full executable files written in Swift and Objective-C, a more robust and harder-to-inspect approach. Second, the attackers have adopted the Pluggable Authentication Modules (PAM) API to verify passwords, rather than the more commonly seen dscl utility. Help Net Security notes this is a fairly new technique for macOS malware, first observed in the wild in July 2026 in the Pam Stealer family.
The PAM API approach is worth paying attention to: using a lower-level system interface for credential verification is harder to detect with tools that watch for the more obvious dscl calls, and its appearance across two separate macOS malware families in quick succession suggests others may follow.
What macOS Users Should Do
Kaspersky advises macOS users to avoid executing commands found online, to steer clear of DMG files from unverified sources, and to treat unexpected admin password prompts with caution. The MacSync malware iCloud calendar technique is a reminder that public, cloud-hosted infrastructure (the kind that blends in with legitimate traffic) is increasingly attractive as a staging ground. Using a service as mundane as a shared calendar event to ferry shellcode is exactly the sort of move that slips past defences focused on more traditional C2 patterns. Kaspersky’s full technical breakdown is available on Securelist.

