Kaspersky has identified a new infection chain for MacSync malware that conceals malicious commands within the description fields of public iCloud calendar events. This development raises questions about how attackers leverage trusted Apple infrastructure to obscure their activities during the initial stages of an attack.

The malware family, first observed on the dark web in 2025 under the name Mac.c, operates on a malware-as-a-service model. Researchers first spotted this specific iCloud-based variant in the wild in September 2026. Unlike previous versions that shared similarities with the Atomic macOS Stealer, or AMOS, MacSync has developed distinct capabilities. Attackers typically spread the initial payload through social engineering, ClickFix-style attacks, or by disguising it as free software and cracked applications.

In the specific attack vector identified by Kaspersky, a downloader component connects to a public iCloud calendar. The attackers place malicious instructions inside the event description field. When the malware feeds this calendar data into the Mac's zsh command-line shell, most of the text produces errors because the system does not recognize standard calendar information as commands. However, the specific malicious instructions placed after the description field execute successfully. These commands download a compressed archive from iCloud containing another malicious app, which initiates the next stage of the infection. Kaspersky noted that while at least one sample used a public iCloud calendar, other samples relied on attacker-controlled servers.

Researchers also found instances where attackers disguised MacSync as a fake cryptocurrency wallet named Toria. Kaspersky reported that criminals built a dedicated website for this nonexistent wallet and promoted it on X and Telegram. This tactic targets crypto owners, as stealing wallet data or browser extension information can lead to financial theft. However, MacSync targets a broader range of sensitive data regardless of cryptocurrency ownership. The information-stealing component searches for browser history, cookies, saved logins, passwords, and Keychain files. It also collects system details such as installed apps, running processes, and hardware information.

For developers and advanced users, the malware poses additional risks by searching configuration files for SSH, ZSH, AWS, Kubernetes, and Git. It also gathers ZSH and Bash command histories. Kaspersky discovered a separate backdoor component written in Objective-C that disguises itself as Finder, the built-in file-management app. This backdoor uses several methods to persist on the Mac after a restart, including LaunchAgents and modifications to .zshrc configuration files and global Git hooks. It can also terminate macOS notification processes to prevent alerts about new LaunchAgents.

Once established, attackers can send instructions to the infected machine via a command-and-control server. Researchers identified commands designed to deploy browser extensions, replace installed Ledger wallet apps, and collect additional system files. Most of these commands execute AppleScript supplied by the attacker. Kaspersky inferred the function of these commands from their names and status messages, as researchers did not possess the actual AppleScript payloads. One command, named live_browser, downloads and executes a component called sn_relay. Kaspersky stated that the exact contents and purpose of sn_relay remain unknown, though researchers suspect it may be used for man-in-the-middle attacks against browser traffic based on its name and server messages.

Apple states that macOS includes multiple layers of protection against such threats. Gatekeeper, XProtect, and Apple's notarization system help prevent malicious software from running. Apple recommends downloading software from the Mac App Store as the safest option. For apps downloaded elsewhere, macOS uses notarization and XProtect to detect known malware. On macOS 26.4 and later, Apple added Terminal paste protection that warns users when text is pasted into Terminal from common attack sources like web browsers or messaging apps. XProtect can also inspect activity starting from pasted commands and block behavior associated with known malware techniques.

Safari includes Fraudulent Website Warning to alert users about suspected phishing sites and Apple Safe Browsing to block malicious domains. Apple emphasizes that social engineering remains a significant part of these attacks, urging users to download software only from trusted sources and keep their systems updated. Users are advised to be cautious when websites request commands be pasted into Terminal or when unfamiliar apps ask for administrator passwords.