← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

MacSync Malware Uses Public iCloud Calendars for Payload Delivery

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • MacSync malware uses public iCloud calendar events for payload delivery.
  • A new Objective-C backdoor module disguises itself as Finder.
  • Malware establishes persistence via LaunchAgent, .zshrc, and Git hooks.
  • It targets browser data, crypto wallets, Telegram, and system files.

MacSync Evolves Delivery Method

The MacSync info-stealing malware, first observed in April 2025, has updated its delivery mechanism for macOS systems. It now leverages public iCloud calendar events to fetch new payloads. This method allows the malware to retrieve additional components and a new backdoor module, marking an evolution from its earlier versions which were derived from the AMOS stealer family.

Infection Chain Details

MacSync is distributed through social engineering tactics, including ClickFix campaigns disguised as legitimate tools like Homebrew or macOS disk space analyzers. Researchers also noted distribution as a fake crypto wallet called Toria, complete with a dedicated website and social media promotion. In the updated delivery chain, a downloader retrieves commands embedded in the description field of a public iCloud calendar event, subsequently downloading the next-stage payload from iCloud. These commands are then executed via the zsh shell.

New Backdoor Functionality

While the infostealer module continues to target browser history, cookies, credentials, crypto wallet data, Telegram data, Keychain files, and various system configuration files, a significant addition is a new Objective-C backdoor. This backdoor masquerades as Finder, the default macOS file manager. It establishes persistence through a LaunchAgent, modifications to .zshrc, and global Git hooks, while also terminating macOS notification processes to avoid user alerts.

Backdoor Capabilities

The new backdoor module enables several actions on compromised systems. It can execute attacker-supplied AppleScript commands received from its command-and-control (C2) server. It can also deploy browser extensions or replace legitimate Ledger wallet applications with malicious versions from the C2 server. Furthermore, the backdoor collects additional system information and files for upload to the C2 server and ensures its persistence across reboots.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~17 min · 13 stories · Sep 25

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

A new variant of the MacSync info-stealing malware for macOS now uses public iCloud calendar events to deliver subsequent payloads. This evolution allows the malware to retrieve additional components and a new Objective-C backdoor, enhancing its persistence and data exfiltration capabilities.