Security researchers have identified a new version of Mac-targeting malware, called MacSync, that can embed malicious commands inside a public iCloud calendar event as part of its infection process. The hidden instructions help the malware download additional malicious software onto a victim’s computer.
Kaspersky, the cybersecurity firm that documented the malware, says simply receiving or viewing a calendar invitation does not infect a Mac. The attack begins earlier, typically after a user downloads and runs a malicious app. But researchers say the iCloud technique shows how attackers can conceal parts of an attack behind trusted, familiar services.
MacSync is an information-stealing malware family that shares similarities with an earlier threat known as the Atomic macOS Stealer, or AMOS. Kaspersky says it first surfaced on the dark web in 2025 under the name Mac.c before being renamed MacSync. The latest version was first observed in the wild in September 2026.
The malware operates on a malware-as-a-service model, meaning different criminal groups can deploy it while choosing their own delivery method. Attackers have previously spread MacSync through social engineering, through so-called ClickFix attacks that trick users into copying and running a command, and by disguising it as free software, cracked applications or unfamiliar apps.
How the iCloud calendar trick works
Kaspersky found one MacSync infection chain in which a downloader connected to a public iCloud calendar. Rather than scheduling anything, attackers placed malicious commands inside the event description field. The malware feeds that calendar data into the Mac’s zsh command-line shell. Most of the text produces errors, since the Mac does not recognize ordinary calendar information as commands, but the hidden instructions placed after the description field can execute. They ultimately download a compressed archive from iCloud containing another malicious app, triggering a further stage of infection.
Kaspersky notes that at least one sample pointed to a public iCloud calendar, while other samples instead used attacker-controlled servers.
Researchers also found MacSync disguised as a fake cryptocurrency wallet called Toria, complete with a dedicated website and promotion on X and Telegram.
What the malware can steal
Once installed, MacSync searches for browser history, cookies, saved logins and passwords, cryptocurrency wallet extension data, wallet applications and Telegram information. It can also collect a user’s login information, Keychain file, installed apps, running processes, hardware details and device model. For developers, the malware searches configuration files for SSH, ZSH, AWS, Kubernetes and Git, and can collect ZSH and Bash command histories.
Kaspersky also discovered a separate backdoor component written in Objective-C that disguises itself as Finder, the built-in macOS file-management app. It attempts to persist on a Mac after restart through a LaunchAgent, changes to the .zshrc configuration file, and modifications to global Git hooks, and can terminate macOS notification processes to hide the new LaunchAgent from the user.
Researchers found commands apparently designed to deploy a browser extension, replace an installed Ledger wallet app, and collect additional system information or files, most executing AppleScript supplied by an attacker’s command-and-control server. Kaspersky says it inferred these functions from command names and status messages, since it did not obtain the actual AppleScript payloads. A command called live_browser downloads a component called sn_relay, whose exact purpose remains unknown; researchers suspect it may relate to intercepting browser traffic but have not confirmed how it works.
Built-in protections and what users can do
Apple says macOS includes layered defenses, including Gatekeeper, XProtect and a notarization system for software downloaded outside the Mac App Store. On macOS 26.4 and later, Apple added Terminal paste protection, which can warn users when text is pasted into Terminal from sources such as web browsers, messaging apps or email. XProtect can also inspect activity triggered by pasted commands and scan AppleScript and JavaScript for Automation scripts for known malicious signatures. Safari’s Fraudulent Website Warning and Apple’s Safe Browsing Service are designed to flag or block malicious domains.
Apple recommends getting software through the Mac App Store when possible, and keeping macOS updated.
Security researchers recommend several additional precautions: avoid pasting unfamiliar commands into Terminal at a website’s instruction; be wary when an unfamiliar app asks for an administrator password; remove unused browser extensions; enable two-factor authentication on sensitive accounts; and use a password manager to create strong, unique passwords, prioritizing email and financial accounts first.
Because MacSync still depends on convincing someone to run malicious software at the outset, researchers say users retain meaningful opportunities to stop the attack before it begins.
