bleeping-computer · Crawled Sep 25, 2026

MacSync malware uses public iCloud calendars to deliver new payloads

1 IoCs
Read original article ↗

AI Summary

A new variant of the MacSync info-stealing malware targeting macOS systems has evolved to use public iCloud calendar events as a delivery mechanism for new payloads. Distributed via social engineering and fake applications such as a counterfeit crypto wallet called Toria, the malware retrieves commands from the description field of a public iCloud calendar, which are then executed in the macOS zsh shell. The infection chain leads to the deployment of a backdoor module written in Objective-C that masquerades as Finder, establishes persistence via LaunchAgent, .zshrc modifications, and Git hooks, and can execute remote AppleScripts, deploy malicious browser extensions, and exfiltrate system data.

AI-extracted · verify before operational use

Indicators of Compromise 1 extracted

Type Value Detail
Filename sn_relay Details →