# MacSync

Published articles for MacSync.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## MacSync malware uses public iCloud calendars to deliver new payloads

DevFeed: [MacSync malware uses public iCloud calendars to deliver new payloads](<https://devfeed.tech/articles/macsync-malware-uses-public-icloud-calendars-to-deliver-new-payloads-59599.md>)

Original publisher: [Read original article](<https://www.bleepingcomputer.com/news/security/macsync-malware-uses-public-icloud-calendars-to-deliver-new-payloads/>)

Author: Bill Toulas

Published: 2026-09-24T20:53:35Z

Content type: news

Language: en

Sources: [BleepingComputer](<https://devfeed.tech/sources/bleepingcomputer.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [macOS](<https://devfeed.tech/topics/macos.md>), [backdoor](<https://devfeed.tech/topics/backdoor.md>), [C2](<https://devfeed.tech/topics/c2.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>)

Tags: [backdoor](<https://devfeed.tech/tags/backdoor.md>), [c2](<https://devfeed.tech/tags/c2.md>), [clickfix](<https://devfeed.tech/tags/clickfix.md>), [computer-help](<https://devfeed.tech/tags/computer-help.md>), [computer-security](<https://devfeed.tech/tags/computer-security.md>), [computers](<https://devfeed.tech/tags/computers.md>), [icloud](<https://devfeed.tech/tags/icloud.md>), [info-stealer](<https://devfeed.tech/tags/info-stealer.md>), [information-stealer](<https://devfeed.tech/tags/information-stealer.md>), [infosec](<https://devfeed.tech/tags/infosec.md>), [infosec-computer-security](<https://devfeed.tech/tags/infosec-computer-security.md>), [linux](<https://devfeed.tech/tags/linux.md>), [mac](<https://devfeed.tech/tags/mac.md>), [macos](<https://devfeed.tech/tags/macos.md>), [macsync](<https://devfeed.tech/tags/macsync.md>), [malware](<https://devfeed.tech/tags/malware.md>), [malware-removal](<https://devfeed.tech/tags/malware-removal.md>), [security](<https://devfeed.tech/tags/security.md>), [spyware](<https://devfeed.tech/tags/spyware.md>), [support](<https://devfeed.tech/tags/support.md>), [tech-support](<https://devfeed.tech/tags/tech-support.md>), [technical-support](<https://devfeed.tech/tags/technical-support.md>), [virus](<https://devfeed.tech/tags/virus.md>), [virus-removal](<https://devfeed.tech/tags/virus-removal.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

A new MacSync infostealer variant for macOS uses commands hidden in public iCloud calendar event descriptions to fetch additional malware payloads. Researchers also observed a new backdoor module that establishes persistence, runs attacker-supplied AppleScript, and can collect and upload data to its command-and-control server.

### Source excerpt

A new variant of the MacSync malware targeting macOS systems now uses public iCloud calendar events to deliver new native payloads. [...]

## MacSync under the microscope: new delivery methods and a new payload

DevFeed: [MacSync under the microscope: new delivery methods and a new payload](<https://devfeed.tech/articles/macsync-under-the-microscope-new-delivery-methods-and-a-new-payload-59229.md>)

Original publisher: [Read original article](<https://securelist.com/macsync-new-version/121383/>)

Author: Sergey Puzan

Published: 2026-09-24T10:00:21Z

Content type: article

Language: en

Sources: [Securelist](<https://devfeed.tech/sources/securelist.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [macOS](<https://devfeed.tech/topics/macos.md>), [backdoor](<https://devfeed.tech/topics/backdoor.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [ClickFix](<https://devfeed.tech/topics/clickfix.md>), [Objective-C](<https://devfeed.tech/topics/objective-c.md>), [Swift](<https://devfeed.tech/topics/swift.md>), [Script](<https://devfeed.tech/topics/script.md>), [Shell](<https://devfeed.tech/topics/shell.md>)

Tags: [apple-macos](<https://devfeed.tech/tags/apple-macos.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [clickfix](<https://devfeed.tech/tags/clickfix.md>), [cryptocurrencies](<https://devfeed.tech/tags/cryptocurrencies.md>), [full](<https://devfeed.tech/tags/full.md>), [infostealers](<https://devfeed.tech/tags/infostealers.md>), [large](<https://devfeed.tech/tags/large.md>), [macos](<https://devfeed.tech/tags/macos.md>), [macsync](<https://devfeed.tech/tags/macsync.md>), [malware](<https://devfeed.tech/tags/malware.md>), [malware-descriptions](<https://devfeed.tech/tags/malware-descriptions.md>), [malware-technologies](<https://devfeed.tech/tags/malware-technologies.md>), [medium](<https://devfeed.tech/tags/medium.md>), [objective-c](<https://devfeed.tech/tags/objective-c.md>), [script](<https://devfeed.tech/tags/script.md>), [shell](<https://devfeed.tech/tags/shell.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [swift](<https://devfeed.tech/tags/swift.md>), [thumbnail](<https://devfeed.tech/tags/thumbnail.md>), [trojan](<https://devfeed.tech/tags/trojan.md>), [trojan-stealer](<https://devfeed.tech/tags/trojan-stealer.md>), [unix-and-macos-malware](<https://devfeed.tech/tags/unix-and-macos-malware.md>)

### AI overview

This report examines a new MacSync macOS infostealer infection chain observed in September 2026. It describes a shift from script-based droppers to binary payload delivery, malware modules written in Objective-C and Swift, and the use of iCloud during infection. MacSync is distributed through malware-as-a-service, social engineering, fake applications, and ClickFix-style attacks.

### Source excerpt

We look at a new version of the MacSync macOS stealer with a backdoor module that targets crypto enthusiasts and developers.