Trusence Technology, daily
Last updated 26 September 2026 Türkçe
← All stories
Security

MacSync malware abuses public iCloud calendars to stage macOS attacks

The Swift-based MacSync backdoor uses iCloud calendar events to pull later payloads and run remote AppleScript commands on infected Macs.

Kaspersky researchers found a MacSync operation targeting macOS that, in its more elaborate delivery route, uses a public iCloud calendar entry to fetch instructions and retrieve later malware stages from iCloud. MacSync first appeared in April 2025, and observed lures have included ClickFix fake utilities and a bogus crypto wallet named Toria promoted on social networks. A newly identified Objective-C component impersonates Finder and sets persistence through a LaunchAgent, zsh startup-file edits and Git hooks, while suppressing alerts by stopping notification services. The backdoor can accept AppleScript commands from its C2, install a browser extension or replace Ledger software, and upload system details and files. Kaspersky could not establish what the live_browser command’s downloaded sn_relay component is for.

Why it matters

MacSync’s use of public iCloud calendar events to obtain commands and download later payloads gives attackers a discreet way to manage macOS infections using Apple’s own cloud infrastructure, rather than obvious malware servers. Once installed, the backdoor can persist through multiple startup mechanisms while silently terminating notification processes and executing AppleScript from its command-and-control server, allowing flexible remote control of compromised systems and making infections harder for users to notice or remove.

Sources

  • BleepingComputer