Close Menu
Mozbot
    Facebook X (Twitter) Instagram
    Button
    MozbotMozbot
    Facebook X (Twitter) Instagram YouTube
    • About us
    • Technology
    • Gadgets
    • Apps & Software
      • Computing
    • News
    • Contact Us
    • Article Submissions
    Mozbot
    Home » News » MacSync Malware Uses iCloud Calendar Events to Stage New Payloads
    Technology

    MacSync Malware Uses iCloud Calendar Events to Stage New Payloads

    Gary BehanBy Gary Behan05/10/2026No Comments4 Mins Read
    Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Email
    MacSync malware iCloud calendar
    Share
    Facebook Twitter Pinterest Reddit WhatsApp Email

    A fresh variant of the MacSync malware iCloud calendar technique has surfaced, with the Swift-based infostealer now hiding attacker commands inside publicly accessible iCloud calendar event descriptions to pull down next-stage payloads. Kaspersky researchers uncovered the campaign, detailing a malware family that has grown considerably more capable since it first emerged as a variant of the AMOS stealer family in April 2025.

    How the MacSync iCloud Calendar Delivery Chain Works

    The more complex of the two delivery methods Kaspersky identified involves a downloader that retrieves commands hidden in the description field of a public iCloud calendar event. Those commands are passed directly to macOS’s zsh shell. Most of the calendar text produces errors and goes nowhere, but instructions placed after the event’s DESCRIPTION: line execute cleanly, fetching an archive that contains the next-stage components.

    That downloaded archive holds an ‘APP’ bundle acting as a dropper. According to Securelist, the malicious payload inside the dropper is a zlib-compressed executable encrypted with AES in CBC mode, a layer of obfuscation that makes static analysis considerably more awkward. From there, further stages eventually retrieve the MacSync malware itself.

    The simpler delivery route leans on social engineering, including ClickFix-style attacks and software presented as free, cracked, or new applications. Kaspersky notes the threat actor distributed MacSync disguised as a fake crypto wallet called Toria, complete with a dedicated website and social media promotion. Other lures have included fake Homebrew installers and macOS disk space analyser tools.

    A New Backdoor Module Disguised as Finder

    The infostealer module itself remains largely unchanged. It targets browser history, cookies, and saved credentials, along with crypto wallet extension and app data, Telegram data, the Keychain file, system information, SSH, AWS, Kubernetes, Git, and shell configuration files. The expansion comes from a new Objective-C backdoor that disguises itself as Finder, macOS’s default file manager.

    The backdoor’s installer establishes persistence through a LaunchAgent, .zshrc modifications, and global Git hooks. It also terminates macOS notification processes, which prevents alerts from reaching the user while it operates. Once in place, the backdoor can run attacker-supplied AppleScript received from its command-and-control (C2) server, deploy or replace browser extensions (including swapping out a legitimate Ledger wallet app for an attacker-controlled version), collect additional files and upload them to the C2 server, and re-establish persistence after a reboot.

    Kaspersky noted a ‘mystery’ command, live_browser, which downloads and executes a component called sn_relay, the purpose of which Kaspersky could not determine. The researchers inferred the purposes of other commands from their names and status messages, since the actual AppleScript code those commands would execute was not available to them.

    MacSync’s Evolving Techniques

    Two details from Help Net Security illustrate how quickly MacSync has matured. First, the new version has moved away from AppleScripts and now uses full executable files written in Swift and Objective-C, a more robust and harder-to-inspect approach. Second, the attackers have adopted the Pluggable Authentication Modules (PAM) API to verify passwords, rather than the more commonly seen dscl utility. Help Net Security notes this is a fairly new technique for macOS malware, first observed in the wild in July 2026 in the Pam Stealer family.

    The PAM API approach is worth paying attention to: using a lower-level system interface for credential verification is harder to detect with tools that watch for the more obvious dscl calls, and its appearance across two separate macOS malware families in quick succession suggests others may follow.

    What macOS Users Should Do

    Kaspersky advises macOS users to avoid executing commands found online, to steer clear of DMG files from unverified sources, and to treat unexpected admin password prompts with caution. The MacSync malware iCloud calendar technique is a reminder that public, cloud-hosted infrastructure (the kind that blends in with legitimate traffic) is increasingly attractive as a staging ground. Using a service as mundane as a shared calendar event to ferry shellcode is exactly the sort of move that slips past defences focused on more traditional C2 patterns. Kaspersky’s full technical breakdown is available on Securelist.

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Email
    Previous ArticleGitLab email token exposure lets attackers open merge requests as you
    Next Article Bitget North Korea crypto hack: stolen funds revised up to $387.5 million
    Gary Behan

    Software engineer and video game uber-nerd.

    Related Posts

    Anthropic Offers Free Credits for Claude Code Cloud Sessions, With a Catch

    06/10/2026

    Rydox marketplace guilty plea lands Kosovar admin facing 22 years

    06/10/2026

    Bitget North Korea crypto hack: stolen funds revised up to $387.5 million

    06/10/2026

    GitLab email token exposure lets attackers open merge requests as you

    05/10/2026

    FedRAMP VDR VER Compliance: What the December Deadline Actually Demands

    05/10/2026

    Windows 11 KB5124010 update arrives with 46 fixes and Copilot key remapping

    04/10/2026
    Add A Comment

    Comments are closed.

    Categories
    • Apps & Software
    • Artificial Intelligence
    • Business
    • Computing
    • Education
    • Energy
    • Featured
    • Finance
    • Gadgets
    • Gaming
    • Health and Safety
    • Home
    • Lifestyle
    • Marketing
    • Medical
    • News
    • NFT
    • Opinions
    • Social
    • Technology
    • Travel & Tourism
    Mozbot
    Facebook X (Twitter) Instagram Pinterest
    © 2026 M0ZBOT. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.