Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

MacSync Info‑Stealing Malware Uses iCloud Calendar to Hide Malicious Commands

Kaspersky discovered a new MacSync variant that spreads via a fake crypto‑wallet app and hides malicious commands in a public iCloud calendar. The campaign targets macOS credentials, crypto‑wallet data and files, illustrating the need for continuous vendor‑risk monitoring and robust endpoint controls for audit readiness.

LiveThreat™ Intelligence · 📅 September 25, 2026· 📰 helpnetsecurity.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
3 recommended
📰
Source
helpnetsecurity.com

MacSync Info‑Stealing Malware Uses iCloud Calendar to Hide Malicious Commands

What Happened – Kaspersky reports a new MacSync variant that delivers an infostealer and persistent backdoor on macOS. The campaign distributes a fake crypto‑wallet app (Toria) that drops a DMG containing Swift/Objective‑C binaries. Malicious commands are concealed inside a public iCloud calendar entry and executed via a Zsh shell, allowing credential, crypto‑wallet and file theft.

Why It Matters for Trust & Control Assurance

  • Demonstrates how a third‑party app can become a supply‑chain conduit for malware, underscoring the need for continuous vendor‑risk monitoring and evidence of due‑diligence.
  • The use of legitimate cloud services (iCloud calendar) to hide commands evades traditional signature‑based detection, highlighting the importance of control mapping and continuous logging to provide a defensible audit trail.
  • Persistent backdoors that erase temporary files stress the requirement for endpoint‑visibility controls that can surface hidden activity in real time.

Who Is Affected – macOS users across all sectors; organizations that allow installation of third‑party desktop applications, especially those in technology, finance and creative industries.

Recommended Actions

  • Enforce a vetted‑application policy and verify code‑signing signatures for all macOS installers.
  • Deploy endpoint detection and response (EDR) that monitors for unusual script execution and calendar‑event‑driven downloads.
  • Incorporate third‑party risk assessments that include supply‑chain checks for apps promoted on social platforms.

Technical Notes – The malware shifts from AppleScript to compiled Swift/Objective‑C executables, uses JXA scripts to decode shell code in‑memory, and leverages an iCloud calendar file as a command‑delivery vector. It includes anti‑VM and anti‑debugger checks, and removes its artifacts after execution. Source: https://www.helpnetsecurity.com/2026/09/25/macsync-info-stealing-malware-for-macos/

📰 Original Source
https://www.helpnetsecurity.com/2026/09/25/macsync-info-stealing-malware-for-macos/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

This is the scenario continuous vendor monitoring is built to catch.

When a vendor is compromised, your third-party risk controls are what produce the audit trail showing you knew, assessed, and acted. The Verisq AI Trust Operations platform tracks that continuously.

Explore the Verisq AI Trust Operations platform →