New MacSync variant hides malicious commands inside public iCloud calendar events
Researchers have identified a fresh MacSync strain that embeds download commands in a public iCloud calendar entry, using it to fetch additional malware after a victim runs a malicious app.
A newly discovered version of the MacSync information-stealer uses a public iCloud calendar entry to conceal commands that download further malicious code onto macOS devices. The attack chain begins when a user runs a malicious application, after which the calendar description is parsed by the zsh shell and the embedded commands execute, pulling a compressed archive from iCloud that launches a second-stage installer. Kaspersky, which first spotted the variant in September 2026, noted that some samples point to the calendar while others use attacker-controlled servers.
The group also distributed the malware under the guise of a bogus crypto-wallet named Toria, complete with a dedicated website and promotion on X and Telegram. Once installed, MacSync can harvest browser data, passwords, crypto-wallet extensions, Keychain files, and configuration files for services such as SSH, AWS and Git. A backdoor component mimics Finder and employs persistence mechanisms like LaunchAgents and.zshrc modifications, while also delivering commands to install malicious browser extensions. Experts advise users to avoid copying terminal commands from unknown sources, download software only from trusted venues, and keep macOS updated to benefit from built-in protections like Gatekeeper and XProtect.
Why it matters
The technique shows how trusted services like iCloud can be abused to hide malware, raising the risk for Mac users who run unverified software.
In this story
