A public iCloud Calendar can look like an unlikely place to hide malware instructions. In one MacSync sample, it was part of the delivery chain.
Kaspersky researchers reported on September 24 that a newer version of the macOS infostealer used a public calendar to retrieve commands that led to another malicious application. For security teams, the finding shows how an attack can use Apple-hosted infrastructure on its way to stealing credentials and installing a backdoor. Kaspersky observed the calendar method in at least one sample; other samples fetched the next stage from an attacker-controlled server.
The calendar does not infect someone simply because they view an event. In the chain Kaspersky analyzed, the victim had already launched a malicious application from a disk image before that application fetched the calendar.
How the calendar enters the infection chain
Kaspersky found MacSync disguised as a nonexistent cryptocurrency wallet app called Toria. Once the malicious app runs, it retrieves a link to its next stage. In the calendar-linked sample, the malware downloads a public calendar file and feeds its contents line by line into the macOS zsh shell. When the shell reaches malicious commands after the calendar’s ‘DESCRIPTION:’ line, they download an archive from iCloud containing another malicious app.
That route differs from the ClickFix campaigns previously tied to MacSync, which trick users into running commands in Terminal. Kaspersky says MacSync is distributed as malware as a service, so the initial lure can vary between operators.
What MacSync can steal
The later stages install both an infostealer and a backdoor, according to Kaspersky. The stealer prompts for the Mac’s administrator password and collects data that can include browser logins and cookies, cryptocurrency wallet files, Keychain material, and SSH, AWS, Kubernetes, and Git configuration files. A later script sets up persistence for the backdoor through a LaunchAgent and commands added to zsh configuration and Git hooks
Those developer and cloud credentials could make an infected work Mac a route into other systems. Earlier reporting on MacSync’s rotating infrastructure also shows why a blocklist alone may miss the threat: defenders need to examine what a process does after it contacts a service.
What security teams should check
Organizations should direct users to official software sources and investigate unexpected apps that request an administrator password. On a suspected device, security teams can look for a sequence involving an unfamiliar app fetching a public calendar, launching shell commands, downloading another app, and accessing sensitive credentials. Kaspersky’s report includes indicators of compromise for the stages it analyzed. Similar caution applies to fake Mac utility downloads, which have also been used to deliver infostealers.
The takeaway is to investigate the full chain, including the app that made the request and the commands that followed it. The public calendar was a delivery step in Kaspersky’s sample; the risk began when the user ran the malicious app.





