MacSync, a Swift-based infostealer originally derived from the AMOS stealer family, has been observed in ClickFix campaigns disguised as Homebrew and macOS disk space analyzer tools. Kaspersky researchers report that the latest variant introduces a novel delivery method: a downloader fetches commands hidden in the description of a public iCloud calendar event. Those commands are then passed to macOS's zsh shell, where text after the DESCRIPTION: line runs and retrieves an archive containing the malware components.
The archive includes an 'APP' bundle that acts as a dropper, leading to further stages that eventually load the MacSync malware. Kaspersky notes that the threat actor also distributed the malware as a fake cryptocurrency wallet called Toria, promoted on a dedicated website and across social media.
Beyond the infostealer module — which targets browser history, cookies, saved credentials, crypto wallet data, Telegram data, Keychain files, SSH and cloud configuration files — the new version adds an Objective-C backdoor. This backdoor disguises itself as Finder and establishes persistence through a LaunchAgent, modifications to .zshrc, and global Git hooks. It also terminates macOS notification processes to prevent alerts from reaching the user.
Once installed, the backdoor can run attacker-supplied AppleScript, deploy a browser extension or replace an installed Ledger wallet app with versions supplied by the command-and-control server, collect system information and files, and re-establish persistence after a reboot. Researchers were unable to determine the purpose of all commands, noting one mystery command and stating they lacked the AppleScript code the backdoor would execute.