Security researchers have identified a new version of Mac-targeting malware called MacSync that can hide malicious commands inside a public iCloud calendar event as part of its infection process. The calendar itself doesn’t infect a computer just by being viewed or shared — the attack still begins with someone downloading and running a malicious app. But researchers say the technique shows how attackers are learning to hide pieces of an attack behind trusted Apple services.
Kaspersky, the cybersecurity firm that uncovered the technique, says MacSync first appeared on the dark web in 2025 under the name Mac.c before its creators renamed it. The newest version was spotted in the wild in September 2026.
How the iCloud trick works
MacSync is distributed under a malware-as-a-service model, meaning different criminals deploy it using their own methods — social engineering, ClickFix-style scams that tell victims to copy and paste a command, or disguising the malware as free software, cracked applications or unfamiliar new apps.
In one infection chain Kaspersky examined, a downloader connected to a public iCloud calendar. Rather than scheduling anything, attackers had placed malicious commands inside the event description. The malware feeds that calendar text into the Mac’s zsh command-line shell. Most of the text produces errors because it isn’t recognized as valid commands, but the hidden instructions after the event description do run, ultimately downloading a compressed archive from iCloud containing another malicious app that launches a further stage of the attack.
Kaspersky notes that at least one sample used a public iCloud calendar this way, while other samples relied on attacker-controlled servers instead.
A fake crypto wallet, too
Researchers also found attackers disguising MacSync as a fake cryptocurrency wallet called Toria, complete with a dedicated website and promotion on X and Telegram.
Once installed, MacSync’s data-stealing component can search browser history, cookies, saved logins and passwords, cryptocurrency wallet extensions and applications, and Telegram data. It can also collect a user’s Keychain file, system and hardware details, and — for developers — configuration files for SSH, ZSH, AWS, Kubernetes and Git, along with command histories.
Kaspersky additionally found a separate backdoor component written in Objective-C that disguises itself as Finder, the macOS file-management app. It tries to persist after a restart through a LaunchAgent, changes to the .zshrc file, and modifications to global Git hooks, while terminating notification processes so the user isn’t alerted to the new LaunchAgent. Researchers found commands apparently designed to deploy a browser extension, replace an installed Ledger wallet app, and collect additional system files — though Kaspersky says it inferred these functions from command names and status messages because it did not obtain the actual payload scripts. A command called live_browser downloads a component called sn_relay, whose exact purpose remains unknown, though researchers suspect it may relate to intercepting browser traffic.
What Apple and researchers recommend
Apple says macOS includes layered protections — Gatekeeper, XProtect and a notarization system for software downloaded outside the Mac App Store — and recommends the App Store as the safest source for Mac software. On macOS 26.4 and later, Apple added Terminal paste protection, which can warn users when text is pasted into Terminal from sources such as browsers or messaging apps, and expanded XProtect scanning to cover AppleScript and JavaScript for Automation scripts.
Security specialists recommend a few basic habits to reduce risk:
- Never paste an unfamiliar command into Terminal because a website tells you to.
- Download software only from the Mac App Store or a developer’s official site, and avoid cracked software or apps promoted mainly through social media.
- Be suspicious if an unfamiliar app suddenly asks for your administrator password.
- Keep macOS updated to the latest version.
- Remove unused browser extensions and investigate unfamiliar ones.
- Turn on two-factor authentication on email, financial and other sensitive accounts, and use a password manager to create unique passwords.
Researchers emphasize that opening iCloud Calendar itself does not put a Mac at risk. The danger lies earlier in the chain — when an unfamiliar app requests a password or a website instructs a user to run a command in Terminal.
You must be logged in to post a comment Login