Hackers Weaponize Public iCloud Calendars To Deploy MacSync Malware

https://images.hothardware.com/contentimages/newsitem/71707/content/16x9_2133x1200_highres-icloud.jpg

Cybersecurity researchers at Kaspersky have uncovered a sneaky new variant of the MacSync malware, revealing a unique tactic where attackers exploit public Apple iCloud calendar events to secretly dump malicious payloads onto macOS devices.

Originally appearing as a simple script-based information stealer derived from the AMOS family, MacSync has evolved into a complex, modular threat delivered through a Malware-as-a-Service model. Distributed via things like fake crypto wallets (like Toria), cracked developer software, and deceptive ClickFix prompts, this infection chain replaces old AppleScript droppers with compiled Swift and Objective-C binary loaders designed to bypass traditional detection mechanisms.

What sets this technique apart is integration of the public iCloud infrastructure. Kaspersky found that in one delivery path, the initial downloader retrieves calendar data formatted as an `.ics` file hosted on public iCloud servers. The downloader feeds this calendar file directly to the system's `zsh` shell. While the vast majority of the...

Copyright of this story solely belongs to hothardware.com. To see the full text click HERE

Read more