MacSync Malware Hides Mac Payload Delivery In An iCloud Calendar
Kaspersky researchers found a new MacSync variant using a fake crypto wallet app, executable payloads and an iCloud calendar handoff to steal Mac credentials, wallet data and files.

Mac users face a revised MacSync malware campaign that pairs an infostealer with a persistent backdoor and hides part of its delivery chain in an iCloud calendar, Help Net Security detailed from Kaspersky research.
The campaign used a fake crypto wallet app called Toria as the lure.
The app had its own website and was promoted through X and Telegram, creating a more complete front for users who believed they were downloading wallet software rather than malware.
MacSync is not a new family.
The malware emerged in 2025 as Mac.c before being renamed, and early versions used AppleScripts that resembled the AMOS stealer.
The latest version, first spotted by Kaspersky in September 2026, changes the execution model and adds a more developed backdoor component.
Sergey Puzan, a malware analyst at Kaspersky, described the new variant as a substantial overhaul because the attackers moved away from AppleScripts and toward executable files written in Swift and Objective-C. That shift matters for defenders because it changes the artifacts and behavior that endpoint tools must watch for on macOS systems.
The infection chain also became more complicated.
One route placed a compiled JXA script inside the DMG.
That script decoded a shell script and passed it directly to the interpreter without writing the script to disk, reducing the visible files available for simple inspection.
A second route used the same script only after droppers and loaders had already run.
The sequence began with an app inside the DMG, which removed its own quarantine attribute and decrypted a hidden link to another downloader.
In some samples, that link led to an attacker-controlled server.
In at least one sample, it led to a public iCloud calendar.
The iCloud detour was operationally useful for the attackers.
The downloader reached the calendar, pulled a base64-encoded payload from the note field of a calendar event, decoded it and launched the next stage.
The resulting chain delivered both the stealer and the backdoor while using Apple infrastructure as an intermediate handoff point.
Once active, MacSync targeted browser data, cryptocurrency wallets and files.
The campaign also gave operators a backdoor for continued access, widening the risk beyond one-time credential theft.
For organizations with Mac fleets, that combination turns a fake app download into a persistence and data-loss problem rather than a nuisance infection.
Kaspersky linked the campaign to one fake app rather than several unrelated lures.
That narrow packaging gives defenders a practical starting point: block the Toria lure, inspect DMG-based installations that remove quarantine attributes, and treat unusual calendar-based payload retrieval as a sign that trusted platform features may be part of an attacker’s delivery path.
The strongest lesson is defensive, not procedural.
Mac security teams cannot assume a familiar infostealer family will keep the same scripting pattern.
This MacSync variant keeps the theft goal but changes the delivery mechanics, leaving detection dependent on the full chain from fake wallet promotion to calendar-hosted payload handoff.












