Malware

MacSync hijacks iCloud calendars to pull in macOS payloads

⏱️ 5 min read📅 9/25/2026👁️ 8 views

MacSync turns iCloud calendars into a covert C2 channel

Instead of talking to a typical server, the latest MacSync variant reads public iCloud calendar event descriptions to receive commands and pull additional payloads.

How the new variant works

The downloader grabs the raw calendar data, pipes it straight into the macOS zsh shell, and runs anything that appears after the DESCRIPTION line. The shell then downloads a compressed archive; the bundle inside is an .app that drops a second‑stage component.

  • Public iCloud calendar event is the command source.
  • Calendar text is fed to zsh for execution.
  • Downloaded archive contains an .app dropper.
  • Dropper launches the next backdoor stage.

Delivery tricks

Kaspersky observed ClickFix‑style campaigns that masquerade as legitimate macOS utilities. Victims see fake Homebrew installers, disk‑space analyzer tools, or even a bogus crypto wallet named “Toria”. Once the user runs the installer, the MacSync payload lands on the system.

Persistence and post‑infection capabilities

After infection, the malware cements itself in several ways:

  • Installs a LaunchAgent that survives reboots.
  • Appends malicious calls to .zshrc so every new terminal session re‑executes the backdoor.
  • Hooks into global Git configurations, ensuring the code runs whenever Git is invoked.

The backdoor can execute attacker‑supplied AppleScript, replace or deploy Ledger wallet applications, harvest system information and user files, and re‑establish persistence after a restart.

Defensive steps

If you manage macOS fleets, treat these indicators as high priority:

  1. Audit LaunchAgents and remove any unknown entries.
  2. Inspect .zshrc and global Git config files for suspicious commands.
  3. Verify the authenticity of any Homebrew, disk‑space, or crypto‑wallet installers before execution.
  4. Monitor network traffic for outbound connections to iCloud calendar URLs and unexpected zsh command executions.
  5. Deploy endpoint protection that can detect the known MacSync binaries and the .app dropper.

Keeping macOS software up‑to‑date and restricting execution of unsigned code remain the most effective shields against this kind of stealthy info‑stealer.

#macOS#info-stealer#iCloud#persistence#AppleScript