New Mac Malware Hides Attack Instructions Inside iCloud Calendar Events

New Mac Malware Hides Attack Instructions Inside iCloud Calendar Events

Security researchers have identified a new version of Mac-targeting malware called MacSync that can hide malicious commands inside a public iCloud calendar event, using it as part of a multi-stage infection chain to download additional malware onto a victim’s computer.

Kaspersky researchers first spotted this version of MacSync in the wild in September 2026. The malware itself does not infect a Mac simply because someone views a calendar invite. The attack still begins earlier, typically after a person downloads and runs a malicious application. But in one infection chain Kaspersky examined, a downloader connected to a public iCloud calendar and fed the event description into the Mac’s zsh command-line shell. Most of that calendar text produced errors, except for hidden commands placed after the description field, which executed and pulled down a compressed archive from iCloud containing another malicious app.

Kaspersky noted that using Apple’s own infrastructure this way can make the attack look less suspicious, though other MacSync samples relied on attacker-controlled servers instead of iCloud.

What MacSync is and how it spreads

MacSync is an information-stealing malware family targeting macOS that shares similarities with an earlier threat known as the Atomic macOS Stealer, or AMOS. According to Kaspersky, it first appeared on the dark web in 2025 under the name Mac.c before its creators renamed it MacSync.

It operates under a malware-as-a-service model, meaning different criminals can deploy it using their own methods. Kaspersky says attackers have spread it through social engineering, ClickFix-style scams that trick people into pasting commands into Terminal, and by disguising it as free software, cracked applications or unfamiliar new apps.

In one case, researchers found MacSync disguised as a fake cryptocurrency wallet called Toria, complete with its own dedicated website and promotion on X and Telegram.

What the malware can steal

Once installed, MacSync searches for browser history, cookies, saved logins and passwords, cryptocurrency wallet extension data, wallet applications and Telegram information. It can also collect a user’s Keychain file and login details, along with system information such as installed apps, running processes, hardware details and device model.

Developers and advanced users face additional exposure, since the malware searches configuration files tied to SSH, ZSH, AWS, Kubernetes and Git, and can collect ZSH and Bash command histories.

Kaspersky also found a separate backdoor component written in Objective-C that disguises itself as Finder, the file-management app built into macOS. It tries to persist on an infected Mac through a LaunchAgent, changes to the .zshrc configuration file, and modifications to global Git hooks, while terminating notification processes to keep the user from noticing. Researchers found commands designed to deploy a browser extension, replace an installed Ledger wallet app, and collect additional files, most of which execute attacker-supplied AppleScript. One command, called live_browser, downloads a component whose exact purpose Kaspersky has not confirmed, though researchers suspect it may relate to intercepting browser traffic.

Built-in protections and what to do

Apple says macOS includes layered protections against malicious software, including Gatekeeper, XProtect and a notarization system for apps downloaded outside the Mac App Store, which Apple recommends as the safest source for software. On macOS 26.4 and later, Apple added Terminal paste protection, which can warn users when text is pasted into Terminal from sources such as web browsers, messaging apps and other communication software. XProtect can also inspect activity triggered by pasted commands and scan AppleScript and JavaScript for Automation scripts for known malicious signatures.

Security researchers recommend a few basic precautions:

  • Be suspicious of any website that asks you to open Terminal and paste a command, whether framed as a CAPTCHA check, a browser fix or a download step.
  • Get software only through the Mac App Store or a developer’s official website, and avoid cracked software or programs promoted mainly through social media.
  • Stop and verify before entering your administrator password if an unfamiliar app requests it unexpectedly.
  • Keep macOS updated to the latest version to benefit from current security patches.
  • Remove browser extensions you don’t recognize or no longer use.
  • Turn on two-factor authentication on email, financial and other sensitive accounts, and consider using a password manager.

The malware still depends on a person running a malicious app at the outset, which means the usual precautions around downloads and Terminal commands remain the most effective way to avoid infection.

Author picture

Leave a Replay

Recent Posts

Sign up for Joe's Newsletter, The Daily Informant