MacSync malware uses public iCloud calendars to deliver new payloads

MacSync malware uses public iCloud calendars to deliver new payloads
A new MacSync variant is targeting macOS users by hiding its payload delivery in public iCloud calendar events, adding a more evasive infection chain. The malware continues stealing browser, crypto, and system data while also introducing an Objective-C backdoor that can run AppleScript, deploy extensions, and maintain persistence. #MacSync #iCloud #macOS #Finder #Toria

Keypoints

  • MacSync is a Swift-based info-stealer that first appeared in April 2025.
  • Attackers deliver it through ClickFix lures and fake cracked or free software.
  • A new delivery method hides commands in public iCloud calendar event descriptions.
  • The malware steals browser, wallet, Telegram, Keychain, SSH, AWS, Kubernetes, and Git data.
  • A new backdoor module disguises itself as Finder and uses persistence techniques like LaunchAgents and Git hooks.

Read More: https://www.bleepingcomputer.com/news/security/macsync-malware-uses-public-icloud-calendars-to-deliver-new-payloads/