MacSync malware evolves with iCloud calendar delivery and new backdoor capabilities

A new variant of the MacSync macOS stealer uses public iCloud calendar events to hide command payloads, adding a Finder-disguised backdoor and server-side decryption to evade static analysis.
Key points
- Kaspersky identified a new MacSync delivery chain that fetches commands from public iCloud calendar descriptions.
- The malware now includes an Objective-C backdoor disguised as Finder, establishing persistence via LaunchAgents and Git hooks.
- A custom utility named pkgunpack uses Curve25519 key exchange to decrypt payloads only with live C2 server cooperation.
- The infostealer module collects browser data, crypto wallet info, and system credentials, verifying passwords via the PAM API.
- Threat actors distribute the malware through ClickFix attacks and fake crypto wallet sites like Toria and Wavel.
Background
MacSync emerged in April 2025 as a Swift-based stealer derived from the AMOS family. Earlier coverage in August 2026 noted Microsoft linking over 30 domains to its infrastructure, highlighting rotating C2 endpoints and chunked data exfiltration. The malware has since evolved from AppleScript-based droppers to binary modules, increasing its evasion capabilities.
How outlets are covering it
Kaspersky and Securelist emphasize the technical shift to binary droppers and the use of iCloud calendars for payload delivery, noting the addition of a backdoor module. The Hacker News focuses on the related PamStealer variant, highlighting similar server-side decryption chains and PAM-based password verification. TechRadar provides a general overview of the iCloud calendar tactic without deep technical detail. All sources agree on the increased sophistication of macOS malware, but Kaspersky and Securelist provide the most granular analysis of the MacSync-specific infection chain.
Why it matters
The use of public iCloud calendars for payload delivery exploits a trusted Apple service, making detection harder. The addition of a backdoor and server-side decryption prevents static analysis, forcing defenders to rely on dynamic monitoring. This evolution signals a shift toward more evasive, modular malware targeting macOS users, particularly developers and crypto enthusiasts.
What to watch
Security researchers expect more macOS malware to adopt server-side decryption and trusted service abuse. Users are advised to avoid executing online commands and downloading DMG files from unverified sources. Kaspersky recommends monitoring for unusual LaunchAgent and Git hook modifications.
- MacSync malware uses public iCloud calendars to deliver new payloads bleepingcomputer.com
- PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence The Hacker News
- A new version of the MacSync macOS stealer targets crypto enthusiasts and developers Securelist
- This Mac malware is somehow using iCloud calendar invites to try and steal your data techradar.com
- PamStealer Moves to Swift With Server-Side Decryption SOC Prime
Want the full story? Read the original reporting
Read on bleepingcomputer.com