Overview
MacSync malware targeting macOS systems has evolved with a new delivery technique that uses public iCloud calendar events to retrieve commands and additional payloads. The malware, which emerged in 2025, has previously been distributed through ClickFix-style social engineering, fake software and cryptocurrency applications. Its latest version introduces a more sophisticated infection chain and an additional backdoor module, extending its capabilities beyond credential and information theft. The development highlights a growing security challenge: trusted cloud services can increasingly become part of malicious infrastructure without the service itself being compromised.
How the New Delivery Chain Works
In one observed infection chain, a downloader retrieves instructions hidden inside the description of a public iCloud calendar event. Those instructions are passed to the macOS zsh shell, which downloads an archive containing additional malware components. The process eventually installs MacSync on the device. Using iCloud in this way gives attackers an advantage because communication with legitimate cloud platforms may appear less suspicious than connections to newly created or obviously malicious domains.
From Infostealer to Persistent Backdoor
MacSync continues to target valuable information stored on macOS devices, including browser history, cookies, saved credentials, cryptocurrency wallets, Telegram data, Keychain information and configuration files associated with SSH, AWS, Kubernetes and Git. Researchers also identified a new Objective-C backdoor disguised as Finder. The module establishes persistence using LaunchAgents, .zshrc modifications and Git hooks, while attempting to suppress macOS notifications. It can execute attacker-supplied AppleScript, retrieve additional files and potentially replace browser extensions or cryptocurrency wallet applications.
Trusted Services Are Becoming Part of the Attack Surface
The use of public iCloud calendars reflects a wider shift in attacker infrastructure. Malware increasingly abuses legitimate cloud, collaboration and development services because these platforms are already trusted by users and organisations. Blocking the entire service may be operationally unrealistic, while malicious activity can be difficult to distinguish from legitimate traffic. This places greater importance on behavioural detection, process monitoring and endpoint telemetry rather than relying exclusively on domain reputation or static network indicators.
Strengthening macOS Security
macOS endpoints should receive the same security attention as Windows systems, particularly where they provide access to cloud platforms, development environments or privileged identities. Application control, endpoint detection, restricted script execution and monitoring of persistence mechanisms can help reduce exposure. Unexpected shell activity, unusual LaunchAgents and suspicious modifications to Git or shell configuration files should warrant investigation. Users should also remain cautious when websites or installation guides instruct them to copy commands into Terminal or install software outside trusted distribution channels.
Expert in the Cloud Insight
MacSync demonstrates how malware architecture is adapting to the modern cloud environment. Attackers no longer need to build every component of their infrastructure themselves when trusted platforms can be abused to deliver instructions and payloads. The security challenge therefore extends beyond identifying malicious domains. Modern detection increasingly needs to answer a more important question:
Is a trusted service being used in a trusted way?
As malware continues to blend into legitimate cloud traffic, visibility into endpoint behaviour, identity activity and application execution will become increasingly important.
Trust in the platform should never automatically translate into trust in the activity travelling through it.
Leave a Reply