MacSync Variant Uses Public iCloud Calendar to Stage Malware

Kaspersky found a MacSync variant using a public iCloud Calendar to deliver malicious commands. See how it works and what security teams should investigate.

Written By
Michelle Lojo
Michelle Lojo
Sep 28, 2026
2 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

A public iCloud Calendar can look like an unlikely place to hide malware instructions. In one MacSync sample, it was part of the delivery chain.

Kaspersky researchers reported on September 24 that a newer version of the macOS infostealer used a public calendar to retrieve commands that led to another malicious application. For security teams, the finding shows how an attack can use Apple-hosted infrastructure on its way to stealing credentials and installing a backdoor. Kaspersky observed the calendar method in at least one sample; other samples fetched the next stage from an attacker-controlled server. 

The calendar does not infect someone simply because they view an event. In the chain Kaspersky analyzed, the victim had already launched a malicious application from a disk image before that application fetched the calendar.

How the calendar enters the infection chain

Kaspersky found MacSync disguised as a nonexistent cryptocurrency wallet app called Toria. Once the malicious app runs, it retrieves a link to its next stage. In the calendar-linked sample, the malware downloads a public calendar file and feeds its contents line by line into the macOS zsh shell. When the shell reaches malicious commands after the calendar’s ‘DESCRIPTION:’ line, they download an archive from iCloud containing another malicious app.

That route differs from the ClickFix campaigns previously tied to MacSync, which trick users into running commands in Terminal. Kaspersky says MacSync is distributed as malware as a service, so the initial lure can vary between operators. 

What MacSync can steal

The later stages install both an infostealer and a backdoor, according to Kaspersky. The stealer prompts for the Mac’s administrator password and collects data that can include browser logins and cookies, cryptocurrency wallet files, Keychain material, and SSH, AWS, Kubernetes, and Git configuration files. A later script sets up persistence for the backdoor through a LaunchAgent and commands added to zsh configuration and Git hooks

Those developer and cloud credentials could make an infected work Mac a route into other systems. Earlier reporting on MacSync’s rotating infrastructure also shows why a blocklist alone may miss the threat: defenders need to examine what a process does after it contacts a service. 

Advertisement

What security teams should check

Organizations should direct users to official software sources and investigate unexpected apps that request an administrator password. On a suspected device, security teams can look for a sequence involving an unfamiliar app fetching a public calendar, launching shell commands, downloading another app, and accessing sensitive credentials. Kaspersky’s report includes indicators of compromise for the stages it analyzed. Similar caution applies to fake Mac utility downloads, which have also been used to deliver infostealers. 

The takeaway is to investigate the full chain, including the app that made the request and the commands that followed it. The public calendar was a delivery step in Kaspersky’s sample; the risk began when the user ran the malicious app.

Read more: Fake Claude Code install pages show how familiar software workflows can lead users to run infostealer payloads.

Michelle Lojo

Michelle Lojo is the News Editor for eWeek, bringing eight years of experience in journalism. She leads coverage of the developments, companies, and emerging trends influencing enterprise technology. Her editorial work focuses on delivering clear, well-researched reporting that helps business and IT leaders understand a rapidly changing technology landscape.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.