<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/macsync-malware-uses-public-icloud-calendars-to-deliver-new-payloads-wo0xysmdq" -->

---
title: MacSync malware uses public iCloud calendars to deliver...
description: A new variant of the MacSync macOS info-stealing malware now abuses public iCloud calendar events to deliver additional payloads. Kaspersky researchers found a...
canonical: https://daily.dev/posts/macsync-malware-uses-public-icloud-calendars-to-deliver-new-payloads-wo0xysmdq
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: MacSync malware uses public iCloud calendars to deliver new payloads | daily.dev
og:description: A new variant of the MacSync macOS info-stealing malware now abuses public iCloud calendar events to deliver additional payloads. Kaspersky researchers found a...
og:url: https://daily.dev/posts/macsync-malware-uses-public-icloud-calendars-to-deliver-new-payloads-wo0xysmdq
og:image: https://api.daily.dev/og/posts/wO0xysmDq.png
og:image:alt: MacSync malware uses public iCloud calendars to deliver new payloads
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# MacSync malware uses public iCloud calendars to deliver new payloads

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 3 min read · 0 upvotes · 0 comments

## Summary

A new variant of the MacSync macOS info-stealing malware now abuses public iCloud calendar events to deliver additional payloads. Kaspersky researchers found a downloader that hides commands in an iCloud calendar event's description field, feeds them to zsh, and downloads a next-stage archive with an APP bundle dropper. MacSync has been spread via ClickFix attacks disguised as Homebrew or disk-analyzer tools, and as a fake crypto wallet called Toria. A newly observed Objective-C backdoor module disguises itself as Finder, establishes persistence via LaunchAgent, .zshrc, and Git hooks, runs attacker-supplied AppleScript, can swap in a malicious browser extension or fake Ledger wallet app, and exfiltrates system data. Users are advised to avoid running commands found online and to be cautious with DMG downloads and admin password prompts.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/macsync-malware-uses-public-icloud-calendars-to-deliver-new-payloads>

## Questions this post answers

### How does the MacSync macOS malware use iCloud calendars to deliver payloads?

A downloader fetches attacker commands hidden in the description field of a public iCloud calendar event, then feeds that text to macOS's zsh shell. Most of the calendar text produces errors, but commands placed after the event's DESCRIPTION line execute and fetch an archive containing an APP bundle dropper that retrieves the MacSync malware.

_Track evolving macOS malware delivery techniques like this on daily.dev to keep endpoint defenses current._

### What can the new MacSync backdoor module do on an infected Mac?

The Objective-C backdoor disguises itself as Finder, establishes persistence through a LaunchAgent, .zshrc modifications, and global Git hooks, and terminates notification processes to hide alerts. It can run attacker-supplied AppleScript, deploy malicious browser extensions, replace an installed Ledger wallet app with a fake version, and exfiltrate system data to its command-and-control server.

_Security teams hardening macOS fleets follow malware capability breakdowns like this via daily.dev._

### How is MacSync malware typically distributed to victims?

MacSync spreads through social engineering including ClickFix-style attacks disguised as Homebrew or disk-space analyzer tools, and through software presented as free, cracked, or new applications. One notable campaign used a fake crypto wallet called Toria with a dedicated website promoted on social media to lure macOS users into installing the malware.

_Anyone vetting Mac software sources can follow malware distribution patterns like these on daily.dev._

## Similar posts on daily.dev

- [MacSync Stealer: How a Google Search for Claude Led to a macOS Infostealer](https://daily.dev/posts/macsync-stealer-how-a-google-search-for-claude-led-to-a-macos-infostealer-rq1vl8kjj) · Huntress Blog · 0 upvotes · 0 comments

---

Tags: [#malware](https://daily.dev/tags/malware), [#mac](https://daily.dev/tags/mac)

[View this post on daily.dev](https://daily.dev/posts/macsync-malware-uses-public-icloud-calendars-to-deliver-new-payloads-wo0xysmdq)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"MacSync malware uses public iCloud calendars to deliver new payloads","url":"https://daily.dev/posts/macsync-malware-uses-public-icloud-calendars-to-deliver-new-payloads-wo0xysmdq","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/macsync-malware-uses-public-icloud-calendars-to-deliver-new-payloads-wo0xysmdq"},"datePublished":"2026-09-24T20:56:58.127Z","dateModified":"2026-09-24T20:58:14.782Z","description":"A new variant of the MacSync macOS info-stealing malware now abuses public iCloud calendar events to deliver additional payloads. Kaspersky researchers found a...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/c6cf731ef92f414e0eb0ad90e53126bc?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/c6cf731ef92f414e0eb0ad90e53126bc?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"BleepingComputer","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"BleepingComputer","logo":"https://media.daily.dev/image/upload/s--as8nJ3qy--/f_auto,q_auto/v1774959951/logos/bleepingcomputer?_a=BAMAMiWQ0","url":"https://daily.dev/sources/bleepingcomputer"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/macsync-malware-uses-public-icloud-calendars-to-deliver-new-payloads-wo0xysmdq","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"malware,mac","timeRequired":"PT3M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"BleepingComputer","item":"https://daily.dev/sources/bleepingcomputer"},{"@type":"ListItem","position":3,"name":"MacSync malware uses public iCloud calendars to deliver new payloads"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/macsync-malware-uses-public-icloud-calendars-to-deliver-new-payloads-wo0xysmdq#faq","mainEntity":[{"@type":"Question","name":"How does the MacSync macOS malware use iCloud calendars to deliver payloads?","acceptedAnswer":{"@type":"Answer","text":"A downloader fetches attacker commands hidden in the description field of a public iCloud calendar event, then feeds that text to macOS's zsh shell. Most of the calendar text produces errors, but commands placed after the event's DESCRIPTION line execute and fetch an archive containing an APP bundle dropper that retrieves the MacSync malware. Track evolving macOS malware delivery techniques like this on daily.dev to keep endpoint defenses current."}},{"@type":"Question","name":"What can the new MacSync backdoor module do on an infected Mac?","acceptedAnswer":{"@type":"Answer","text":"The Objective-C backdoor disguises itself as Finder, establishes persistence through a LaunchAgent, .zshrc modifications, and global Git hooks, and terminates notification processes to hide alerts. It can run attacker-supplied AppleScript, deploy malicious browser extensions, replace an installed Ledger wallet app with a fake version, and exfiltrate system data to its command-and-control server. Security teams hardening macOS fleets follow malware capability breakdowns like this via daily.dev."}},{"@type":"Question","name":"How is MacSync malware typically distributed to victims?","acceptedAnswer":{"@type":"Answer","text":"MacSync spreads through social engineering including ClickFix-style attacks disguised as Homebrew or disk-space analyzer tools, and through software presented as free, cracked, or new applications. One notable campaign used a fake crypto wallet called Toria with a dedicated website promoted on social media to lure macOS users into installing the malware. Anyone vetting Mac software sources can follow malware distribution patterns like these on daily.dev."}}]}
```

