MacSync malware uses public iCloud calendars to deliver new payloads
Key Points:
- A new variant of MacSync malware targeting macOS now uses public iCloud calendar events to deliver payloads, leveraging a downloader that extracts commands from calendar descriptions to fetch malware components.
- MacSync, initially derived from the AMOS stealer family, has evolved with modular capabilities, including a new Objective-C backdoor disguised as the Finder app that establishes persistence and disables macOS notifications to avoid detection.
- The malware steals a wide range of data such as browser history, cookies, credentials, crypto wallet data, Telegram info, Keychain files, and system configurations, while the backdoor can execute AppleScripts, deploy malicious browser extensions, and replace Ledger wallet apps.
- Delivery methods include social engineering campaigns like ClickFix-style attacks and fake crypto wallets promoted on social media, with the malware disguised as legitimate tools such as Homebrew or disk space analyzers.
- Kaspersky advises macOS users to avoid running unknown commands, downloading DMG files from untrusted sources, and to be cautious with admin password prompts to mitigate infection risks from evolving MacSync campaigns.