Skip to main content

Morning Overview

A Mac malware hides its commands inside public iCloud calendar invites

A strain of Mac malware called MacSync is retrieving its attack instructions from public iCloud calendar invites instead of a traditional command server, Kaspersky researchers reported this week. The technique lets an infected Mac quietly check a calendar entry anyone could view, pull commands hidden in its description field, and fetch new components without contacting a server that antivirus tools would flag as suspicious. Kaspersky researcher Sergey Puzan published the findings on the company’s Securelist blog on Sept. 24, 2026.

A public iCloud calendar as a covert command channel

The mechanism works by abusing a feature meant for scheduling, not code delivery. A downloader component fetches a specific public iCloud calendar event and feeds its text straight into the Mac’s zsh shell. Most of the calendar entry’s wording is treated as garbled, invalid commands that the shell simply rejects, and nothing in that behavior looks unusual to security software watching for network traffic to a known malicious server.

The interpreter keeps reading past those rejected lines until it hits a marker buried further down in the event description. As Kaspersky’s report explains, “the interpreter treats the lines as invalid commands until it reaches the malicious payload after the DESCRIPTION: line,” at which point the hidden instructions execute and pull down the next stage of the attack. Using a calendar this way also gives the operators a way to update payloads on the fly: change the text of one shared event, and every infected Mac checking in against it picks up new commands without the malware ever needing to be recompiled or redistributed.

PAM hijacking and what MacSync actually steals

Once installed, MacSync’s infostealer module reaches well beyond browser passwords. Kaspersky and BleepingComputer’s separate reporting both describe it pulling browser history, cookies and saved credentials; crypto wallet extension and app data, including Ledger-related files; Telegram data and Keychain files; and configuration files for SSH, AWS, Git and Kubernetes — the kind of access that matters far more on a software developer’s laptop than on a casual user’s.

To grab a Mac’s local account password, MacSync verifies guesses through the operating system’s Pluggable Authentication Modules, or PAM, rather than the dscl utility most Mac stealers rely on. Kaspersky calls PAM-based credential theft “a fairly new technique for macOS malware,” one first spotted in the wild only in July 2026, in an unrelated family called Pam Stealer. Sergey Puzan warned that “MacSync’s compromise of software developers’ devices poses particular security risks for both end users and corporate systems, opening up expanded opportunities for attackers to further their intrusion.”

From an AppleScript AMOS clone to a Finder-disguised backdoor

MacSync did not start out this sophisticated. Kaspersky traces its origins to April 2025, when early versions were written in AppleScript and closely resembled the Atomic macOS Stealer, or AMOS, a subscription malware-as-a-service tool that Palo Alto Networks’ Unit 42 says has been advertised to criminals on Telegram since April 2024 and remains in active development. Kaspersky’s report says the AppleScript-based tool “was later renamed to MacSync by its creators” as it grew more advanced.

The current version has moved well past its AppleScript roots. It now ships a Swift-based infostealer alongside a separate Objective-C backdoor that disguises itself as the Mac’s own Finder application, giving attackers remote AppleScript execution, the ability to deploy malicious browser extensions and multiple ways to survive a restart through LaunchAgents and shell configuration files.

The Toria wallet lure and the ClickFix trick behind it

Kaspersky and Help Net Security’s coverage of the report both point to a fake cryptocurrency wallet called Toria, built with its own website and promoted on X and Telegram, as the newest lure aimed at developers and crypto enthusiasts. Earlier MacSync campaigns disguised the same payload as everyday Mac utilities, including Homebrew installers and disk-space analyzer tools, plus outright cracked software downloads.

Many of those lures rely on ClickFix, a social-engineering trick first documented by Proofpoint in 2024 in which a fake error message or verification prompt talks a person into copying a command and pasting it into their own machine’s terminal or run dialog. Proofpoint’s original description put it bluntly: “The ClickFix social engineering technique uses dialogue boxes containing fake error messages to trick people into copying, pasting, and running malicious content on their own computer.” On a Mac, that single pasted command is often enough to launch MacSync’s downloader and start the calendar check-ins that follow.

Kaspersky has not said how many Mac users have been infected by the calendar-based variant, and Apple has not commented on the report. The company’s calendar-sharing feature itself is not compromised — MacSync simply uses it the way any public webpage could be used, as a place to hide text only its downloader is looking for.

This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.


More from Morning Overview