MacSync info-stealing malware hides malicious commands in an iCloud calendar

MacSync info-stealing malware hides malicious commands in an iCloud calendar
Kaspersky has uncovered a new MacSync variant that uses an infostealer and a persistent backdoor to steal credentials, crypto wallet data, files, and developer-related information from Mac users. The campaign spreads through a fake crypto wallet app called Toria and uses advanced infection chains, disguised prompts, and a backdoor posing as Finder to target developers and crypto enthusiasts. #MacSync #Kaspersky #Toria #Finder #Ledger #PAM #Keychain

Keypoints

  • MacSync has evolved into a more advanced Mac infostealer and backdoor threat.
  • The malware was distributed through the fake crypto wallet app Toria.
  • Attackers used multi-stage droppers, loaders, and even a public iCloud calendar in the infection chain.
  • The stealer harvests browser data, Keychain data, crypto wallet files, Telegram data, and developer configs.
  • The backdoor disguises itself as Finder and can reinstall itself through persistence mechanisms.

Read More: https://www.helpnetsecurity.com/2026/09/25/macsync-info-stealing-malware-for-macos/