< Back to all clusters
[TECHNOLOGY] · 5 sources

started · updated

MacSync malware uses iCloud calendars to infect macOS

A new evolution of the MacSync info-stealing malware is targeting macOS systems by utilizing public iCloud calendar events to deliver malicious payloads. This method allows the malware to use legitimate Apple infrastructure to host commands and archives, making detection more difficult.

The infection chain typically begins with social engineering, such as ClickFix campaigns or fake software like cryptocurrency wallets and developer tools. In more complex attacks, a downloader retrieves commands hidden within the description field of a public iCloud calendar event. These commands are then fed to the macOS zsh shell to fetch the next stage of the malware.

MacSync has expanded its capabilities with a new Objective-C backdoor module that disguises itself as the macOS Finder to establish persistence. The primary infostealer module targets sensitive data, including browser history, cookies, saved credentials, cryptocurrency wallet data, Telegram information, Keychain files, and various configuration files for SSH, AWS, and Kubernetes.

Entities

Apple · Kaspersky · MacSync · iCloud