MacSync info-stealing malware hides malicious commands in an iCloud calendar
Kaspersky says a new MacSync macOS infostealer hides commands in an iCloud calendar and steals credentials and wallets.
Kaspersky reported a September 2026 MacSync variant delivered through a fake crypto wallet app called Toria and promoted on X and Telegram. The chain uses DMG droppers, Swift and Objective-C binaries, and in one case shell commands hidden after the DESCRIPTION line of a public iCloud calendar. The stealer prompts for an administrator password through the PAM API, then collects browser secrets, wallets, Keychain, Telegram, SSH, AWS, Kubernetes, and Git data. An Objective-C backdoor masquerades as Finder, persists via a LaunchAgent, .zshrc, and Git hooks, and can run attacker AppleScript.