MacSync turns iCloud calendars into a covert C2 channel
Instead of talking to a typical server, the latest MacSync variant reads public iCloud calendar event descriptions to receive commands and pull additional payloads.
How the new variant works
The downloader grabs the raw calendar data, pipes it straight into the macOS zsh shell, and runs anything that appears after the DESCRIPTION line. The shell then downloads a compressed archive; the bundle inside is an .app that drops a second‑stage component.
- Public iCloud calendar event is the command source.
- Calendar text is fed to
zshfor execution. - Downloaded archive contains an
.appdropper. - Dropper launches the next backdoor stage.
Delivery tricks
Kaspersky observed ClickFix‑style campaigns that masquerade as legitimate macOS utilities. Victims see fake Homebrew installers, disk‑space analyzer tools, or even a bogus crypto wallet named “Toria”. Once the user runs the installer, the MacSync payload lands on the system.
Persistence and post‑infection capabilities
After infection, the malware cements itself in several ways:
- Installs a LaunchAgent that survives reboots.
- Appends malicious calls to
.zshrcso every new terminal session re‑executes the backdoor. - Hooks into global Git configurations, ensuring the code runs whenever Git is invoked.
The backdoor can execute attacker‑supplied AppleScript, replace or deploy Ledger wallet applications, harvest system information and user files, and re‑establish persistence after a restart.
Defensive steps
If you manage macOS fleets, treat these indicators as high priority:
- Audit LaunchAgents and remove any unknown entries.
- Inspect
.zshrcand global Git config files for suspicious commands. - Verify the authenticity of any Homebrew, disk‑space, or crypto‑wallet installers before execution.
- Monitor network traffic for outbound connections to iCloud calendar URLs and unexpected
zshcommand executions. - Deploy endpoint protection that can detect the known MacSync binaries and the
.appdropper.
Keeping macOS software up‑to‑date and restricting execution of unsigned code remain the most effective shields against this kind of stealthy info‑stealer.