This Mac malware somehow uses iCloud calendar invites to try to steal your data
- Kaspersky uncovers MacSync, a Mac information stealer delivered via iCloud calendar events and fake apps
- The loader obtains instructions from calendar entries and then deploys malware that extracts credentials, wallets, and developer data.
- Newer variants add Objective-C backdoor spoofing Finder, persistence, and expanded targeting to cryptocurrency and IT users.
Cybercriminals have found a way to use iCloud calendar events and cloud storage to deliver a powerful information stealer to Mac devices.
The malware is called MacSync and hides behind fake crypto wallets or “cracked” trading software.
Kaspersky security researchers, who discovered the ongoing campaign, urge Mac users to be careful when downloading programs, especially from third-party websites, and to be very skeptical of applications that ask for your administrator password.
Latest videos ofTechnologyRadar
Why calendar?
Getting people to download and run malware on their devices is not as easy as it seems.
Victims need to be tricked into downloading and running an app somehow, and even when they do, the malicious program is likely to be detected by whatever antivirus solution the device is running, before it can cause significant damage. Additionally, criminals do not want to be forced to repeat the process every time they want to deploy a different variant or type of malware.
Therefore, they resort to all kinds of techniques and solutions, from downloading DLL files to malware loaders.
By separating the initial infection and the actual malware, cybercriminals can reduce the detection rate and gain more flexibility, but it creates a new problem: defenders can monitor traffic going in and out of different applications and thus detect when a loader is deploying malware.
The challenge then is to hide the traffic, and MacSync does this using iCloud calendar.
After being downloaded and executed, the loader will approach the calendar (which is a completely benign activity that is unlikely to raise suspicion) and look for a specific public event, pre-crafted by the attackers. In its description, you will find the instructions and location of the real information thief and implement it to ultimately compromise the target device. In this case, the location was also in iCloud.
The uploader itself advertises through social media, SEO poisoning and phishing. Victims are directed to fraudulent websites or social media channels that promote cracked software or free versions of advanced solutions. In at least one example, Kaspersky saw the charger advertised as a cryptocurrency wallet. Victims are shown a typical ClickFix error and told to fix it by pasting a command into Terminal.
The command deploys the loader which, in turn, installs MacSync.
A “substantial” review
The data stealer emerged in April 2025 and initially emerged from AMOS, one of the most popular data stealing variants for MacOS. It is based on Swift and has since evolved to offer additional capabilities. According to Kaspersky, it can filter browser history, cookies, saved credentials, app and cryptocurrency wallet data, Telegram data, keychain data, as well as system and device information. You can also filter SSH, AWS, Kubernetes, Git, and Shell configuration files.
Newer variants come with an Objective-C backdoor that spoofs macOS’s default file manager, Finder. It establishes persistence, terminates notification processes to prevent alerts, and grants attackers backdoor access, including executing AppleScript received from the C2 server, deploying browser extensions, replacing the legitimate Ledger wallet app, collecting additional system information, and more.
Kaspersky also found an undefined command called “live_browser,” which downloads and runs a component called “sn_relay,” the point of which has not yet been set.
The new versions differ “significantly” from previous ones, Kaspersky said, noting that the attackers “substantially” revised their approach.
“The nature of the data that the attackers seek to collect from the victim’s device, as well as the categories of applications under which the thief disguises himself, clearly indicate that this malware family primarily targets developers, cryptocurrency enthusiasts, and other users associated in some way with IT and the crypto space,” the researchers emphasized. “MacSync’s compromise with software developers’ devices poses particular security risks to both end users and corporate systems, opening up greater opportunities for attackers to further their intrusion.”
The full list of Indicators of Compromise (IoC) can be found at this link.
The best antivirus for all budgets
Follow TechRadar on Google News and add us as a preferred source to receive news, reviews and opinions from our experts in your feeds.



Post Comment