MacSync malware uses public iCloud calendars to deliver new payloads

A sophisticated variant of the MacSync info-stealing malware has been discovered, utilizing public iCloud calendars to deliver fresh payloads to macOS systems. This new tactic allows the threat actor to distribute malware without relying on traditional methods such as phishing or drive-by downloads.

The MacSync malware, which emerged in April 2025, is a Swift-based program that has evolved significantly over time. Initially derived from the AMOS stealer family, it has added new capabilities via modules and now incorporates an Objective-C backdoor that disguises itself as Finder, the default file manager on macOS. This advanced module enables the malware to perform various actions on infected systems, including running attacker-supplied AppleScript code, deploying browser extensions or replacing installed apps with versions from a command-and-control (C2) server, and collecting system information and files for upload.

The discovery was made by Kaspersky researchers, who identified two delivery methods used by the threat actor. In one method, a downloader fetches commands hidden in the description of a public iCloud calendar event and then downloads the next-stage payload from iCloud. The downloader feeds the retrieved calendar data to macOS’s zsh shell, where most of the text produces errors but commands placed after the event’s DESCRIPTION: line run and fetch an archive containing the malware components.

This new tactic highlights the ongoing evolution of MacSync and its increasing sophistication in evading detection. As a result, it is essential for macOS users to exercise caution when interacting with online content. The researchers advise against executing commands found online and recommend avoiding downloads from suspicious sites, as well as treating admin password prompts with skepticism.

The inclusion of a “mystery” command, live_browser, which downloads and executes a component called sn_relay, whose purpose is unknown, adds to the complexity of the malware’s functionality. This highlights the ongoing cat-and-mouse game between threat actors and security researchers, where new tactics and techniques are constantly being developed.

The implications of this discovery are significant, as it demonstrates the ability of MacSync to adapt and evolve in response to changing circumstances. As a result, macOS users must remain vigilant and take proactive steps to protect themselves from these types of threats. By doing so, they can minimize the risk of falling victim to this sophisticated malware and maintain the security of their systems.

In light of this development, it is essential for all macOS users to review their online habits and ensure that they are taking adequate precautions to prevent malware infections. This includes avoiding suspicious downloads, exercising caution when interacting with online content, and keeping software up-to-date with the latest security patches. By doing so, they can significantly reduce the risk of falling victim to this type of attack and maintain the integrity of their systems.


Source: Bleeping Computer — 2026-09-24