malware
Published 2026-09-24
Verified 2026-09-27

MacSync (Kaspersky 24 Sep): public iCloud calendar → zsh loader; new Finder-disguised Objective-C backdoor

Kaspersky Securelist (Sergey Puzan; datePublished 24 September 2026 10:00 UTC) documents a new MacSync macOS stealer infection chain first spotted in the wild in September 2026. MacSync is a Swift/Objective-C crypto/infostealer family first advertised on the dark web around April 2025 (earlier builds resembled AMOS). Delivery includes ClickFix-style lures (fake Homebrew / macOS disk-space tools) and fake apps such as a promoted crypto wallet branded Toria. Complex chain: a downloader pulls commands from the DESCRIPTION: field of a public iCloud calendar event, pipes the calendar text into zsh -s (most lines error; post-DESCRIPTION commands run), then fetches an archive from iCloud containing an APP-bundle dropper that stages MacSync. Infostealer module still harvests browsers, crypto-wallet extensions/apps, Telegram, Keychain, SSH/AWS/Kubernetes/Git/shell configs, and device info. New Objective-C backdoor disguises as Finder; persistence via LaunchAgent com.apple.finder.agent, .zshrc / Git-hook injection, and killing macOS notification processes. C2 AppleScript tasks include deploy_ledger (replace Ledger wallet with C2 copy), browser-extension deploy, regrab exfil, and mystery live_browser → sn_relay component (purpose not determined). Kaspersky detections: HEUR:Trojan.OSX.MacSync.* / Trojan-PSW.OSX.MacSync.*. No CVE. Primary: Kaspersky Securelist; wire: BleepingComputer 24 Sep 2026.

Product
MacSync macOS stealer + Finder-disguised Objective-C backdoor (iCloud calendar / ClickFix / fake Toria wallet)
Versions
n/a (malicious macOS implant; family from ~Apr 2025; Sep 2026 chain adds iCloud calendar loader + backdoor module; no CVE)
Exploited in Australia?
unknown
Patch to
Do not paste Homebrew/ClickFix/verification commands into Terminal; avoid cracked/DMG downloads and unknown crypto-wallet apps (incl. Toria); treat unexpected admin password prompts as hostile; hunt LaunchAgent com.apple.finder.agent, unexpected .zshrc / global Git hooks, and HEUR:Trojan.OSX.MacSync.*; rotate browser, Keychain, SSH, cloud and wallet credentials on suspected infection

Primary: Kaspersky Securelist — MacSync new delivery + backdoor (24 Sep 2026) · Vendor: Kaspersky — MacSync under the microscope · BleepingComputer — MacSync uses public iCloud calendars (24 Sep 2026)

tech identity cloud