MacSync malware uses public iCloud calendars to deliver new payloads
MacSync macOS infostealer now pulls new payloads from public iCloud calendar events and adds a persistent backdoor.
Kaspersky reports a new MacSync macOS infostealer variant that hides next-stage commands in the description of a public iCloud calendar event. A downloader feeds that text to zsh, which fetches an archive and an app-bundle dropper that ultimately installs MacSync. The stealer still harvests browser data, Keychain, crypto wallets, Telegram, and cloud and shell credentials. A new Objective-C backdoor, disguised as Finder, persists through a LaunchAgent, .zshrc changes, and global Git hooks, and can run AppleScript and replace a Ledger wallet app.
61