A sophisticated variant of MacSync malware has emerged, targeting macOS systems and using public iCloud calendars as a novel delivery mechanism for fresh payloads. The threat actor behind this campaign has been observed distributing the malware through social engineering tactics, including ClickFix-style attacks and fake software installations.
MacSync is a Swift-based info-stealer that first appeared in April 2025. Initially derived from the AMOS stealer family, it has since evolved to incorporate new capabilities via modules. The threat actor’s use of public iCloud calendars to deliver payloads marks a significant shift in tactics, as this allows them to bypass traditional antivirus detection methods.
The researchers at Kaspersky discovered that the MacSync campaign employed two delivery methods. In the more complex approach, a downloader fetches commands hidden in the description of a public iCloud calendar event. This data is then fed into macOS’s zsh shell, where it retrieves an archive containing the malware components. The archive includes an ‘APP’ bundle that acts as a dropper, leading to further stages that eventually retrieve the MacSync malware.
One notable aspect of this campaign is the introduction of a new Objective-C backdoor module that disguises itself as Finder, the default file manager on macOS. This backdoor allows the attacker to run AppleScript commands received from its command-and-control server, deploy browser extensions or replace installed apps, collect system information and files, and establish persistence across reboots.
The researchers were able to infer the purposes of various commands based on their names and status messages, but a “mystery” command, live_browser, remains unclear. Despite this, it’s evident that MacSync continues to evolve and adopt more evasive and effective distribution chains, making macOS users increasingly vulnerable.
In light of these findings, it’s essential for macOS users to exercise caution when interacting with online commands or downloading files from suspicious sites. Admins should also be vigilant about admin password prompts and avoid executing commands found online. As the threat landscape continues to shift, users must remain proactive in their security posture to mitigate the risks associated with evolving malware threats like MacSync.
To stay ahead of these types of attacks, consider implementing robust security measures such as regularly updating software, using reputable antivirus solutions, and practicing safe browsing habits. By staying informed and taking proactive steps, you can reduce your exposure to sophisticated threats like MacSync and protect your digital assets from harm.
Source: Bleeping Computer — 2026-09-24