A new MacSync variant is targeting macOS users by hiding its payload delivery in public iCloud calendar events, adding a more evasive infection chain. The malware continues stealing browser, crypto, and system data while also introducing an Objective-C backdoor that can run AppleScript, deploy extensions, and maintain persistence. #MacSync #iCloud #macOS #Finder #Toria
Keypoints
- MacSync is a Swift-based info-stealer that first appeared in April 2025.
- Attackers deliver it through ClickFix lures and fake cracked or free software.
- A new delivery method hides commands in public iCloud calendar event descriptions.
- The malware steals browser, wallet, Telegram, Keychain, SSH, AWS, Kubernetes, and Git data.
- A new backdoor module disguises itself as Finder and uses persistence techniques like LaunchAgents and Git hooks.