express gazette logo
The Express Gazette
Sunday, October 4, 2026

Mac Malware Exploits iCloud Calendar for Covert Operations

Researchers identify a new MacSync malware variant that hides malicious commands within public iCloud calendar events to facilitate infections.

US Politics • 2 hours ago
Mac Malware Exploits iCloud Calendar for Covert Operations

Security researchers have discovered a new iteration of MacSync malware that leverages public iCloud calendar events to conceal commands, enabling the download of additional malicious software onto Macs. This tactic exploits a trusted service to obscure parts of the infection chain.

The MacSync malware, first observed in 2025 and identified as a distinct variant in September 2026, is an information-stealing malware family targeting macOS. Earlier versions shared similarities with the AMOS Stealer, but MacSync has since developed its own capabilities. It operates on a malware-as-a-service model, allowing various threat actors to deploy it using different methods, including social engineering, fake software, and disguised applications.

In one documented infection chain, MacSync's downloader connected to a public iCloud calendar. Instead of legitimate event data, attackers embedded malicious commands within the event description. When processed by the Mac's zsh command-line shell, these commands can execute, leading to the download of a compressed archive from iCloud containing a further malicious application, thus advancing the infection.

This method allows attackers to use Apple's infrastructure, potentially making the malicious activity appear less suspicious. While some MacSync samples have utilized iCloud, others have relied on attacker-controlled servers.

Beyond its use of iCloud, MacSync has also been spread by attackers posing as a fake cryptocurrency wallet named Toria. These actors created a dedicated website and promoted it on social media platforms, highlighting how sophisticated social engineering tactics are employed.

Once active on a Mac, MacSync is designed to steal a wide range of sensitive data. This includes browser history, cookies, saved logins, and passwords. It also targets crypto wallet extension data and cryptocurrency wallet applications. The malware can extract Mac user login information and the Keychain file, along with system details like installed applications, running processes, and hardware information. For more advanced users, it can gather configuration files for services like SSH, ZSH, AWS, Kubernetes, and Git, as well as command histories.

A separate backdoor component, disguised as macOS's Finder application, has also been identified. This backdoor employs multiple persistence techniques to remain active after a system restart, including LaunchAgents and modifications to configuration files. Researchers have observed commands intended to deploy browser extensions, replace installed wallet applications, and exfiltrate additional system data.

One particular command, 'live_browser,' remains under investigation. Researchers suspect it may be used for man-in-the-middle attacks on browser traffic, though its exact function is not yet confirmed.

Apple states that macOS has built-in security features such as Gatekeeper, XProtect, and notarization to help prevent malware. Recent macOS versions (26.4 and later) include Terminal paste protection, which warns users when commands are pasted into Terminal from common attack vectors. Apple also recommends downloading software only from trusted sources and keeping the operating system updated.

To protect against MacSync and similar threats, users are advised to avoid copying unfamiliar commands from websites into Terminal, download applications from reputable sources like the Mac App Store, and treat administrator password requests with caution. Employing robust antivirus software, keeping macOS updated, regularly checking browser extensions, enabling two-factor authentication on accounts, and changing passwords if an infection is suspected are also crucial security measures.


Sources