Select a theme from the list.
Insights

From our experts

Latest
Unpatched OnePlus Chain Gives Permissionless Android Apps Root ControlMacSync Turns Public iCloud Calendars Into a Hidden Malware Delivery ChannelStorm-2570 Changes Ransomware Brands but Keeps the Same Attack PlaybookExploited F5 OAuth Flaw Opens a Direct Route Into Access InfrastructureAI Attack Crews Turn Online Stores Into Industrial Card-Skimming TargetsMicrosoft Builds an Agentic Command Center for the Modern SOCOT Segmentation Study Finds Critical Devices Sharing Networks With Everyday ITBifrost Gateway Flaw Opens AI Infrastructure to Unauthenticated Command ExecutionTrustSink Turns a Rogue MFA Provider Into a Silent Password CollectorColorado Water Attacks Show How Small Utilities Become Physical TargetsJade Sleet Turns Developer Interviews Into a Doorway to IT ProvidersStolen Ribon App Credentials Open BigCommerce Stores to Data TheftUnpatched OnePlus Chain Gives Permissionless Android Apps Root ControlMacSync Turns Public iCloud Calendars Into a Hidden Malware Delivery ChannelStorm-2570 Changes Ransomware Brands but Keeps the Same Attack PlaybookExploited F5 OAuth Flaw Opens a Direct Route Into Access InfrastructureAI Attack Crews Turn Online Stores Into Industrial Card-Skimming TargetsMicrosoft Builds an Agentic Command Center for the Modern SOCOT Segmentation Study Finds Critical Devices Sharing Networks With Everyday ITBifrost Gateway Flaw Opens AI Infrastructure to Unauthenticated Command ExecutionTrustSink Turns a Rogue MFA Provider Into a Silent Password CollectorColorado Water Attacks Show How Small Utilities Become Physical TargetsJade Sleet Turns Developer Interviews Into a Doorway to IT ProvidersStolen Ribon App Credentials Open BigCommerce Stores to Data Theft
Security Insight

MacSync Turns Public iCloud Calendars Into a Hidden Malware Delivery Channel

MacSync Turns Public iCloud Calendars Into a Hidden Malware Delivery Channel
Photo by panumas nikhomkhai on Pexels

A new MacSync campaign is hiding delivery instructions inside public iCloud calendar events. The macOS malware can steal credentials and developer secrets, establish several forms of persistence and install a backdoor capable of executing attacker-supplied AppleScript. The technique allows ordinary cloud content to function as an indirect command and payload channel.

News Date: 2026-09-24

A new version of the MacSync information stealer is using public iCloud calendar events to retrieve commands and deliver additional malware to macOS computers. The campaign shows how attackers can hide operational instructions inside legitimate cloud services that users and network controls may be reluctant to block.

Commands Concealed in Calendar Events

MacSync is a Swift-based threat first observed in 2025 and has previously appeared in social-engineering campaigns that impersonated Homebrew, disk-management tools and other applications. In the newly documented activity, the malware was also presented as a cryptocurrency wallet named Toria and promoted through a dedicated website and social media.

In the more complex infection chain, a downloader accesses the description field of a public iCloud calendar event. Content following a specific description marker is passed to the macOS zsh shell, which executes embedded instructions and downloads an archive containing the next stage.

This approach does not mean iCloud itself has been compromised. Instead, the attackers are abusing a legitimate content-hosting feature as a dead-drop location. The malware only needs to retrieve publicly accessible information, making the traffic potentially harder to distinguish from normal cloud activity.

Broad Theft and Persistent Backdoor Access

The information-stealing component targets browser histories, cookies, saved credentials, cryptocurrency wallets, Telegram data and the macOS Keychain. It also searches for SSH material, AWS credentials, Kubernetes configuration, Git data and shell files, making infected developer workstations particularly valuable.

Researchers also identified an Objective-C backdoor disguised as Finder. It can establish persistence through LaunchAgents, shell configuration changes and global Git hooks. The module can execute AppleScript, collect files and replace browser extensions or an installed Ledger wallet application with attacker-controlled versions.

Recommended Controls

  • Prevent users from running copied terminal commands from websites or unsolicited instructions.
  • Restrict software installation to trusted and managed sources.
  • Monitor new LaunchAgents, global Git hooks and unexpected changes to shell configuration files.
  • Investigate unusual password prompts and applications impersonating Finder.
  • Rotate cloud and developer credentials after a suspected infection.

I believe the developer-secret collection is the most serious enterprise concern. A compromised Mac may provide access not only to personal accounts but also to source repositories, cloud environments and deployment systems. Security teams should therefore treat suspicious macOS activity as a potential starting point for a wider infrastructure breach.

Talk to our team →

Latest

Unpatched OnePlus Chain Gives Permissionless Android Apps Root ControlSep 25, 2026MacSync Turns Public iCloud Calendars Into a Hidden Malware Delivery ChannelSep 25, 2026Storm-2570 Changes Ransomware Brands but Keeps the Same Attack PlaybookSep 25, 2026Exploited F5 OAuth Flaw Opens a Direct Route Into Access InfrastructureSep 24, 2026AI Attack Crews Turn Online Stores Into Industrial Card-Skimming TargetsSep 24, 2026Microsoft Builds an Agentic Command Center for the Modern SOCSep 24, 2026

Most read

1Microsoft Redraws the Security Boundary for Edge AI2Ted Implant Turns Compromised HAProxy Servers Into Invisible Interception Points3French Hospital Fine Turns Weak Identity Controls Into a GDPR Warning4Windows LegacyHive Flaw Leaves Administrators Weighing Unofficial Protection5IDScan Lawsuits Put Mass Identity Collection Under the Microscope6COLDCARD Randomness Failure Exposes Bitcoin Wallets to an $88 Million Sweep