New Mac Malware Hides Attack Commands Inside iCloud Calendar Events
New Mac Malware Hides Attack Commands Inside iCloud Calendar Events

Technology

New Mac Malware Hides Attack Commands Inside iCloud Calendar Events

Security researchers at Kaspersky found a new version of the MacSync malware that hides malicious commands inside public iCloud calendar events as part of a multi-stage attack on Macs, though the infection still begins when a user runs a malicious app.

Security researchers have identified a new version of Mac-targeting malware called MacSync that can hide malicious commands inside a public iCloud calendar event as part of its infection process. The calendar itself doesn’t infect a computer just by being viewed or shared — the attack still begins with someone downloading and running a malicious app. But researchers say the technique shows how attackers are learning to hide pieces of an attack behind trusted Apple services.

Kaspersky, the cybersecurity firm that uncovered the technique, says MacSync first appeared on the dark web in 2025 under the name Mac.c before its creators renamed it. The newest version was spotted in the wild in September 2026.

How the iCloud trick works

MacSync is distributed under a malware-as-a-service model, meaning different criminals deploy it using their own methods — social engineering, ClickFix-style scams that tell victims to copy and paste a command, or disguising the malware as free software, cracked applications or unfamiliar new apps.

In one infection chain Kaspersky examined, a downloader connected to a public iCloud calendar. Rather than scheduling anything, attackers had placed malicious commands inside the event description. The malware feeds that calendar text into the Mac’s zsh command-line shell. Most of the text produces errors because it isn’t recognized as valid commands, but the hidden instructions after the event description do run, ultimately downloading a compressed archive from iCloud containing another malicious app that launches a further stage of the attack.

Kaspersky notes that at least one sample used a public iCloud calendar this way, while other samples relied on attacker-controlled servers instead.

A fake crypto wallet, too

Researchers also found attackers disguising MacSync as a fake cryptocurrency wallet called Toria, complete with a dedicated website and promotion on X and Telegram.

Once installed, MacSync’s data-stealing component can search browser history, cookies, saved logins and passwords, cryptocurrency wallet extensions and applications, and Telegram data. It can also collect a user’s Keychain file, system and hardware details, and — for developers — configuration files for SSH, ZSH, AWS, Kubernetes and Git, along with command histories.

Kaspersky additionally found a separate backdoor component written in Objective-C that disguises itself as Finder, the macOS file-management app. It tries to persist after a restart through a LaunchAgent, changes to the .zshrc file, and modifications to global Git hooks, while terminating notification processes so the user isn’t alerted to the new LaunchAgent. Researchers found commands apparently designed to deploy a browser extension, replace an installed Ledger wallet app, and collect additional system files — though Kaspersky says it inferred these functions from command names and status messages because it did not obtain the actual payload scripts. A command called live_browser downloads a component called sn_relay, whose exact purpose remains unknown, though researchers suspect it may relate to intercepting browser traffic.

What Apple and researchers recommend

Apple says macOS includes layered protections — Gatekeeper, XProtect and a notarization system for software downloaded outside the Mac App Store — and recommends the App Store as the safest source for Mac software. On macOS 26.4 and later, Apple added Terminal paste protection, which can warn users when text is pasted into Terminal from sources such as browsers or messaging apps, and expanded XProtect scanning to cover AppleScript and JavaScript for Automation scripts.

Security specialists recommend a few basic habits to reduce risk:

  • Never paste an unfamiliar command into Terminal because a website tells you to.
  • Download software only from the Mac App Store or a developer’s official site, and avoid cracked software or apps promoted mainly through social media.
  • Be suspicious if an unfamiliar app suddenly asks for your administrator password.
  • Keep macOS updated to the latest version.
  • Remove unused browser extensions and investigate unfamiliar ones.
  • Turn on two-factor authentication on email, financial and other sensitive accounts, and use a password manager to create unique passwords.

Researchers emphasize that opening iCloud Calendar itself does not put a Mac at risk. The danger lies earlier in the chain — when an unfamiliar app requests a password or a website instructs a user to run a command in Terminal.

Click to comment

You must be logged in to post a comment Login

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

You May Also Like

Government Corruption

Updated 5/17/19 9:52am Jack Crane | Opinion  James Baker, Former-FBI General Counsel has joined Russian hoax media collaborator Michael Isikoff on his podcast, yesterday....

US Politics

I do not even know where to begin with this one.  Just when you think you have seen the worst that humanity has to...

US News

Education is considered to be one of the pillars of a successful life. Without a college degree, many believe these students will earn lower...

US News

ICYMI| If it were not for Tom Fitton and Judicial Watch, it is more than likely that the world would never know the extent...