Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

MacSync Malware Leverages Public iCloud Calendar Events to Deliver Payloads to macOS Systems

MacSync, a macOS info‑stealer, now hides commands in public iCloud calendar descriptions to fetch additional payloads, targeting browsers, crypto wallets, and cloud credentials. The technique underscores the need for continuous monitoring of legitimate cloud services and endpoint controls for audit readiness.

LiveThreat™ Intelligence · 📅 September 25, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
4 recommended
📰
Source
bleepingcomputer.com

MacSync Malware Leverages Public iCloud Calendar Events to Deliver Payloads to macOS Systems

What Happened — A new variant of the MacSync info‑stealer for macOS uses public iCloud calendar events as a covert command‑and‑control channel. Attackers embed shell commands in the calendar description field; a downloader on the victim’s machine parses the text, executes the commands, and fetches additional payloads from iCloud. The campaign is delivered via social‑engineering (fake crypto‑wallet app, cracked‑software bundles) and adds a persistent backdoor that modifies LaunchAgents, .zshrc, and Git hooks.

Why It Matters for Trust & Control Assurance

  • Demonstrates how legitimate cloud services can be weaponized, highlighting the need for continuous monitoring of third‑party service usage and endpoint behavior.
  • Illustrates a gap in application allow‑listing and script‑execution controls that a control‑assurance program must detect and document.
  • Aligns with the control objective of secure configuration and monitoring of endpoint and cloud interactions, which feeds evidence for multiple frameworks (e.g., NIST CSF, ISO 27001).

Who Is Affected – Enterprises and individuals using macOS devices, especially those that integrate iCloud services for calendar or file sync.

Recommended Actions

  • Deploy macOS‑specific EDR/XDR solutions that flag anomalous shell execution and unexpected iCloud network traffic.
  • Enforce least‑privilege access to iCloud APIs and restrict calendar write permissions to approved applications.
  • Implement application allow‑listing and script‑execution policies (e.g., block unsigned .zshrc modifications).
  • Conduct security‑awareness training focused on fake crypto‑wallet and cracked‑software lures.
  • Continuously map and audit endpoint‑cloud interaction controls to maintain a defensible audit trail. Source: https://www.bleepingcomputer.com/news/security/macsync-malware-uses-public-icloud-calendars-to-deliver-new-payloads/

Technical Notes

  • Delivery vector: social engineering (phishing‑style fake apps) and misuse of public iCloud calendar events.
  • Payloads delivered via iCloud‑hosted archives; backdoor persists through LaunchAgent, .zshrc, and Git hooks.
  • Targets: browser history, cookies, crypto‑wallet extensions, Keychain, SSH keys, AWS/Kubernetes credentials, Git configs, and system information. Source: https://www.bleepingcomputer.com/news/security/macsync-malware-uses-public-icloud-calendars-to-deliver-new-payloads/
📰 Original Source
https://www.bleepingcomputer.com/news/security/macsync-malware-uses-public-icloud-calendars-to-deliver-new-payloads/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →