A new version of the MacSync information-stealing malware is now using public iCloud calendar events to deliver updated payloads to macOS systems, according to Kaspersky researchers. The malware first appeared in April 2025 and has recently been spread through ClickFix campaigns disguised as Homebrew and macOS disk space analyzer tools. It has also been distributed through software advertised as free, cracked, or newly released.
MacSync is a Swift-based threat that earlier versions drew from the AMOS stealer family before evolving with added modules. Kaspersky found the campaign uses two delivery methods, with the more complex one relying on a downloader that retrieves commands hidden in the description of a public iCloud calendar event before pulling the next-stage payload from iCloud. That downloader sends the calendar data to macOS's zsh shell. While most of the calendar text generates errors, commands placed after the event's DESCRIPTION: line execute and retrieve an archive containing the malware components.
The archive holds an APP bundle that functions as a dropper, leading to additional stages that ultimately deliver the MacSync malware. The researchers also observed a new Objective-C backdoor that masquerades as Finder, the default file manager on macOS. Its installer achieves persistence through a LaunchAgent, modifications to .zshrc, and global Git hooks, while killing macOS notification processes to keep alerts from reaching the user.
Kaspersky determined the purpose of the commands from their names and status messages, since it did not possess the AppleScript code they would run. The researchers additionally flagged a command labeled live_browser that downloads and executes a component called sn_relay, whose function Kaspersky could not identify. The threat actor also delivered the malware as a fake crypto wallet named Toria, which had its own website and was promoted across social media platforms.
The findings point to an evolving distribution chain for MacSync, which researchers describe as increasingly evasive and effective. For US macOS users, the campaign underscores the risk of running commands copied from the internet. Kaspersky advises avoiding execution of online commands, steering clear of DMG files from suspicious sites, and treating admin password prompts with caution.
More cybersecurity news from TechManNews.







