< Back to all clusters
[TECHNOLOGY] · 2 sources

started · updated

MacSync malware evolves with backdoor and iCloud calendar exploitation

Researchers at Kaspersky have identified a new, more sophisticated version of the MacSync malware targeting macOS users. This updated variant combines an infostealer with a new backdoor module, significantly increasing its ability to compromise devices.

The malware is primarily distributed through social engineering, ClickFix attacks, and fraudulent DMG files disguised as legitimate software, such as document sharing tools or cryptocurrency wallets. A notable aspect of the infection chain is the exploitation of legitimate Apple infrastructure; specifically, the malware uses public iCloud calendars to host scripts. These scripts, embedded within calendar event descriptions, act as intermediaries to download subsequent malicious components.

Once active, the infostealer component can harvest browser history, cookies, credentials, cryptocurrency wallet data, Telegram information, Keychain files, and configuration files for services like SSH, AWS, and Kubernetes. The newly added backdoor module, which disguises itself as the macOS Finder, allows attackers to execute AppleScripts from a command-and-control server, install browser extensions, replace Ledger wallet applications, and establish persistence to ensure the malware runs upon every system reboot.

Entities

Apple · Kaspersky · MacSync

Sources

about 13 hours ago
2 days ago