bleeping-computer · Crawled Sep 25, 2026
MacSync malware uses public iCloud calendars to deliver new payloads
1 IoCs
Read original article ↗
AI Summary
A new variant of the MacSync info-stealing malware targeting macOS systems has evolved to use public iCloud calendar events as a delivery mechanism for new payloads. Distributed via social engineering and fake applications such as a counterfeit crypto wallet called Toria, the malware retrieves commands from the description field of a public iCloud calendar, which are then executed in the macOS zsh shell. The infection chain leads to the deployment of a backdoor module written in Objective-C that masquerades as Finder, establishes persistence via LaunchAgent, .zshrc modifications, and Git hooks, and can execute remote AppleScripts, deploy malicious browser extensions, and exfiltrate system data.
AI-extracted · verify before operational use
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| Filename | sn_relay | Details → |