A new and highly unusual distribution technique is being used by the administrators of MacSync, a malware that targets macOS systems with the aim of stealing sensitive data. According to Kaspersky, the newest variant of the malware exploits public events in the iCloud Calendar to transmit commands and download additional pieces of malicious code.

This development shows how cybercriminals are looking to legitimate internet services and infrastructure to hide their activity. Rather than relying solely on a traditional server that can be more easily detected and blocked, MacSync uses a service that many users consider completely trustworthy.
From ClickFix to iCloud Calendar
MacSync first appeared in April 2025 and is written in the Swift programming language. It was initially associated with the family AMOS, known for malware aimed at stealing information from Mac computers.
However, MacSync has since evolved and acquired different modules, significantly expanding its capabilities. Attackers distribute it through social engineering techniques, including ClickFix, but also through applications presented as freeware, pirated software , or supposedly useful macOS tools.
In one of the campaigns, the malware even appeared as a fake crypto wallet called Toria. The supposed wallet had its own website and was promoted via social networks, exploiting users' trust in cryptocurrency-related applications.
See also: RemControl: New Android malware steals banking information
iCloud Calendar becomes a distribution channel
The most interesting aspect of the new campaign is how the malware receives its next commands.
Researchers have discovered a downloader that looks for hidden commands within the description of a public iCloud Calendar event. The retrieved data is then piped into the macOS zsh shell.
The event content is not all valid commands and causes errors. However, specific data placed after the "DESCRIPTION:" can be executed and lead to the download of a file containing the next stages of the infection.
The file acts as a dropper, i.e. an intermediate installer that prepares the system for the installation of additional malicious components. Ultimately, through this chain, MacSync is installed.
Using a legitimate service like iCloud can make communication difficult to detect, as malicious activity can be "lost" among normal internet traffic.

What MacSync steals
MacSync's core infostealer mechanism remains particularly dangerous. It targets browsing history, cookies, saved credentials, app and extension data for crypto wallets, as well as information from Telegram.
The malware also searches for data from the Keychain , system and device information, and configuration files related to tools and services such as SSH, AWS, Kubernetes, Git, and shell.
This specific targeting shows that MacSync is not only interested in personal data. Some of the files it searches for may contain credentials, tokens, or access details to development infrastructure and cloud services, which could increase the impact of a successful infection.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Corp MDM malware targets Logistics companies, steals new SMS and redirects calls
New backdoor disguised as Finder
Kaspersky also discovered a new module that adds even more capabilities to MacSync. It is a backdoor written in Objective-Cthat pretends to be the Finder, the default file manager of macOS.
The malicious component is installed using persistence mechanisms, including a LaunchAgent, modifications to .zshrc , and global Git hooks. This allows attackers to maintain access even after a computer reboot.
At the same time, the malware terminates processes related to macOS notifications, limiting the chances of the user noticing suspicious activity.
Backdoor with remote control capability
The new module can receive commands from the command-and-control (C2) server and execute AppleScript provided by the attackers. It can also collect and upload files and additional system information, install browser extensions , and replace crypto wallet applications with versions provided by the C2 server.
Of particular interest is the live_browser, which downloads and executes a component called sn_relay. Kaspersky was unable to determine with certainty the ultimate purpose of this component, which leaves open the possibility that it is part of a different attack mechanism.

What Mac users should watch out for
This campaign is a reminder that the security of a Mac does not solely depend on operating system updates. Social engineering and fake apps remain a key method of initial infection.
See also: AI malware removes humans from the attack chain
Users should avoid executing commands that appear on random websites or pop-ups, even if they are presented as a supposed solution to a Mac problem. Particular attention should also be paid to DMG downloads from unknown sources, pirated applications , and requests for administrator passwords.
MacSync ultimately shows that attackers don’t always need to create impressive or entirely custom infrastructures. Leveraging legitimate services, such as iCloud Calendar, can provide them with a more discreet way to transport commands and payloads. For macOS users, this means that careful software installation and wariness of “patches” that require the execution of unknown commands remain critical protection measures.
source: www.bleepingcomputer.com
