The MacSync info-stealing malware, first observed in April 2025, has updated its delivery mechanism for macOS systems. It now leverages public iCloud calendar events to fetch new payloads. This method allows the malware to retrieve additional components and a new backdoor module, marking an evolution from its earlier versions which were derived from the AMOS stealer family.
MacSync is distributed through social engineering tactics, including ClickFix campaigns disguised as legitimate tools like Homebrew or macOS disk space analyzers. Researchers also noted distribution as a fake crypto wallet called Toria, complete with a dedicated website and social media promotion. In the updated delivery chain, a downloader retrieves commands embedded in the description field of a public iCloud calendar event, subsequently downloading the next-stage payload from iCloud. These commands are then executed via the zsh shell.
While the infostealer module continues to target browser history, cookies, credentials, crypto wallet data, Telegram data, Keychain files, and various system configuration files, a significant addition is a new Objective-C backdoor. This backdoor masquerades as Finder, the default macOS file manager. It establishes persistence through a LaunchAgent, modifications to .zshrc, and global Git hooks, while also terminating macOS notification processes to avoid user alerts.
The new backdoor module enables several actions on compromised systems. It can execute attacker-supplied AppleScript commands received from its command-and-control (C2) server. It can also deploy browser extensions or replace legitimate Ledger wallet applications with malicious versions from the C2 server. Furthermore, the backdoor collects additional system information and files for upload to the C2 server and ensures its persistence across reboots.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
A new variant of the MacSync info-stealing malware for macOS now uses public iCloud calendar events to deliver subsequent payloads. This evolution allows the malware to retrieve additional components and a new Objective-C backdoor, enhancing its persistence and data exfiltration capabilities.