Mac Malware Using iCloud Calendar to Try to Steal Data
Cybercriminals have found a way to use iCloud calendar events and cloud storage to deliver a powerful infostealer to Mac devices.
The malware is called MacSync, and it hides behind a fake crypto wallet, or “cracked” commercial software. Security researchers at Kaspersky, who discovered the ongoing campaign, are urging Mac users to exercise caution when downloading programs, especially from third-party websites, and to be very sceptical of apps prompting for their admin password.

Why calendar?
Getting people to download and run malware on their devices is not as easy as it sounds.
Techradar is reporting that victims need to be tricked into downloading and running an app, and even when they do, the malicious program will likely be sniffed out by whatever antivirus solutions the device has running before it can do any meaningful damage. Also, crooks don’t want to repeat the process every time they want to deploy a different variant or type of malware.
So, they resort to all sorts of techniques and workarounds, from DLL sideloading to malware loaders.
By separating the initial infection from the actual malware, cybercriminals can reduce detection rates and gain more flexibility. Still, it creates a new problem: defenders can monitor traffic going in and out of different apps and detect when a loader deploys malware.
The challenge then becomes hiding the traffic, and MacSync does it by using the iCloud calendar.
After being downloaded and executed, the loader will reach out to the calendar – which is a totally benign activity that is unlikely to raise any suspicion – and look for a specific public event, pre-built by the attackers. In its description, it will find the instructions and the location of the actual infostealer, and deploy it to compromise the target device ultimately. In this case, the location was also in iCloud.
The loader itself is being advertised through social media, SEO poisoning, and phishing. Victims are directed either to fraudulent websites or social media channels promoting cracked software or free versions of advanced solutions. In at least one example, Kaspersky saw the loader being advertised as a cryptocurrency wallet. Victims see a typical ClickFix error and are told to fix it by pasting a command into the Terminal.
The infostealer emerged in April 2025 and was initially spun out of AMOS, one of the most popular information-stealing variants for macOS. It is written in Swift and has since evolved to offer additional capabilities. According to Kaspersky, it can exfiltrate browser history, cookies, saved credentials, cryptocurrency wallet and app data, Telegram data, Keychain data, and system and device information. It can also exfiltrate SSH, AWS, Kubernetes, Git, and shell configuration files.
Newer variants include an Objective-C backdoor that spoofs the macOS default file manager, Finder. It establishes persistence, terminates notification processes to prevent alerts, and grants the attackers backdoor access, including running AppleScript received from the C2 server, deploying browser extensions, replacing the legitimate Ledger wallet app, collecting additional system information, and more.
Kaspersky also found an undefined command called “live_browser”, which downloads and runs a component named “sn_relay”, whose purpose has not yet been established.
Kaspersky said the new versions “significantly” differ from older ones, stressing that the attackers “substantially” overhauled their approach.
“The nature of the data attackers seek to collect from a victim’s device, as well as the categories of applications the stealer disguises itself as, clearly indicates that this malware family primarily targets developers, crypto enthusiasts, and other users associated in some way with IT and the crypto space,” the researchers stressed. “MacSync’s compromise of software developers’ devices poses particular security risks for both end users and corporate systems, opening up expanded opportunities for attackers to further their intrusion.”
The full list of indicators of compromise (IoC) can be found at this link.
