
MacSync Malware Uses Public iCloud Calendars to Target Mac Users
Security researchers have uncovered a new version of the MacSync malware that uses public iCloud calendars as part of its attack chain, an unusual technique that allows the malware to hide malicious instructions inside legitimate Apple-hosted content.
Kaspersky discovered the new MacSync variant in September 2026 while investigating a campaign targeting Mac users. MacSync is an information stealer that first appeared in 2025 and has previously been distributed through fake applications, cracked software, and ClickFix attacks that trick users into running commands in Terminal. The latest version is considerably more sophisticated, combining information-stealing capabilities with a persistent backdoor that can give attackers continued access to an infected Mac.
Hiding Malicious Commands in an iCloud Calendar
In one of the samples analyzed by Kaspersky, MacSync used a publicly accessible calendar hosted on Apple’s iCloud service to retrieve instructions for the next stage of the attack. The attackers placed shell commands inside the description of a calendar event, which the malware downloaded and passed to zsh, the command-line shell included with macOS.
When the hidden commands were reached, they instructed the Mac to download another archive from iCloud and continue the infection process. Eventually, the chain installs MacSync’s main information-stealing and backdoor components. Using iCloud gives the attackers the advantage of communicating with legitimate Apple infrastructure rather than relying entirely on obviously suspicious servers.
Importantly, this doesn’t mean iCloud or Apple’s Calendar app has been compromised, nor can someone infect a Mac simply by sending its owner a calendar invitation. The technique comes into play after the victim has already been tricked into launching malicious software.
MacSync Targets Passwords and Other Sensitive Data
Once running, MacSync searches the Mac for valuable information including browser passwords and cookies, cryptocurrency wallets, Telegram data, Keychain files, and other credentials. It also targets developer-related information such as SSH configuration files, AWS credentials, Git data, and shell command histories.
The malware can display a fake password prompt in an attempt to obtain the Mac user’s administrator password. Its backdoor also establishes persistence so it can survive beyond the initial infection and receive additional commands from its operators.
In the campaign investigated by Kaspersky, MacSync was disguised as a cryptocurrency wallet called Toria. The attackers created a website for the fake wallet and promoted it through social media to make the application appear legitimate.
For Mac users, the new technique is another reason to be cautious about software downloaded outside the App Store or a developer’s known website, particularly applications promoted through advertisements or social media. Users should also be wary of instructions asking them to paste unfamiliar commands into Terminal and unexpected administrator password requests from newly downloaded software.
MacSync’s use of public iCloud calendars doesn’t exploit a vulnerability in Apple’s service, but it does demonstrate how malware developers can abuse trusted online services to make malicious activity harder to recognize.