MacSync malware evolves with iCloud calendar-based payload delivery and new backdoor

Kaspersky researchers detail a novel infection chain that uses public iCloud calendar events to fetch commands, while the malware gains an Objective-C backdoor disguised as macOS Finder.

By LineZotpaper
Published
Read Time2 min
A new variant of the MacSync info-stealing malware for macOS is now using public iCloud calendar events to deliver fresh payloads, according to researchers at Kaspersky. The malware, which first emerged in April 2025, has also added a sophisticated backdoor module that disguises itself as the default macOS file manager, Finder.

MacSync, a Swift-based infostealer originally derived from the AMOS stealer family, has been observed in ClickFix campaigns disguised as Homebrew and macOS disk space analyzer tools. Kaspersky researchers report that the latest variant introduces a novel delivery method: a downloader fetches commands hidden in the description of a public iCloud calendar event. Those commands are then passed to macOS's zsh shell, where text after the DESCRIPTION: line runs and retrieves an archive containing the malware components.

The archive includes an 'APP' bundle that acts as a dropper, leading to further stages that eventually load the MacSync malware. Kaspersky notes that the threat actor also distributed the malware as a fake cryptocurrency wallet called Toria, promoted on a dedicated website and across social media.

Beyond the infostealer module — which targets browser history, cookies, saved credentials, crypto wallet data, Telegram data, Keychain files, SSH and cloud configuration files — the new version adds an Objective-C backdoor. This backdoor disguises itself as Finder and establishes persistence through a LaunchAgent, modifications to .zshrc, and global Git hooks. It also terminates macOS notification processes to prevent alerts from reaching the user.

Once installed, the backdoor can run attacker-supplied AppleScript, deploy a browser extension or replace an installed Ledger wallet app with versions supplied by the command-and-control server, collect system information and files, and re-establish persistence after a reboot. Researchers were unable to determine the purpose of all commands, noting one mystery command and stating they lacked the AppleScript code the backdoor would execute.

§

Analysis

Why This Matters

  • MacSync's use of public iCloud calendars for command delivery represents a novel and stealthy technique that could bypass traditional security tools that do not monitor calendar data as a potential command channel.
  • The addition of a backdoor module significantly expands the malware's capabilities beyond credential theft, enabling attackers to maintain persistent access and deploy further malicious actions.
  • macOS users, especially those in cryptocurrency or development communities, face increased risk from targeted social engineering campaigns masquerading as legitimate tools or wallets.

Background

MacSync first appeared in April 2025 as an info-stealer targeting macOS systems. Its early versions were derived from the AMOS stealer family. Over time, the malware evolved through modular additions. The latest campaign, discovered by Kaspersky, uses two delivery methods: a simpler ClickFix approach and a more complex chain involving iCloud calendars. The threat actor also promoted a fake cryptocurrency wallet called Toria to distribute the malware.

Key Perspectives

Kaspersky researchers: They identified the infection chains, the iCloud calendar technique, and the new backdoor module. They highlight the malware's evolution and the novel use of calendar events as a command channel. Victims: Users who download fake tools or cracked software, or who fall for ClickFix prompts, may unwittingly install MacSync, risking theft of credentials, cryptocurrency, and sensitive files. Apple: As the platform vendor, Apple faces pressure to address this novel abuse of iCloud calendars and the malware's ability to persist via LaunchAgents and Git hooks, potentially through macOS security updates or iCloud policy changes.

What to Watch

  • Whether macOS security features (Gatekeeper, Notarization) effectively block the fake app bundles used in the distribution chain.
  • Any updates from Apple regarding monitoring or restricting the use of public iCloud calendar descriptions for command-like content.
  • Further evolution of MacSync, especially if the mystery command is clarified or if the malware is repurposed in broader campaigns.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.