MacSync Info‑Stealing Malware Uses iCloud Calendar to Hide Malicious Commands
What Happened – Kaspersky reports a new MacSync variant that delivers an infostealer and persistent backdoor on macOS. The campaign distributes a fake crypto‑wallet app (Toria) that drops a DMG containing Swift/Objective‑C binaries. Malicious commands are concealed inside a public iCloud calendar entry and executed via a Zsh shell, allowing credential, crypto‑wallet and file theft.
Why It Matters for Trust & Control Assurance
- Demonstrates how a third‑party app can become a supply‑chain conduit for malware, underscoring the need for continuous vendor‑risk monitoring and evidence of due‑diligence.
- The use of legitimate cloud services (iCloud calendar) to hide commands evades traditional signature‑based detection, highlighting the importance of control mapping and continuous logging to provide a defensible audit trail.
- Persistent backdoors that erase temporary files stress the requirement for endpoint‑visibility controls that can surface hidden activity in real time.
Who Is Affected – macOS users across all sectors; organizations that allow installation of third‑party desktop applications, especially those in technology, finance and creative industries.
Recommended Actions
- Enforce a vetted‑application policy and verify code‑signing signatures for all macOS installers.
- Deploy endpoint detection and response (EDR) that monitors for unusual script execution and calendar‑event‑driven downloads.
- Incorporate third‑party risk assessments that include supply‑chain checks for apps promoted on social platforms.
Technical Notes – The malware shifts from AppleScript to compiled Swift/Objective‑C executables, uses JXA scripts to decode shell code in‑memory, and leverages an iCloud calendar file as a command‑delivery vector. It includes anti‑VM and anti‑debugger checks, and removes its artifacts after execution. Source: https://www.helpnetsecurity.com/2026/09/25/macsync-info-stealing-malware-for-macos/