MacSync malware uses public iCloud calendars to deliver new payloads
A new MacSync variant targeting macOS fetches commands hidden in the description of public iCloud calendar events and downloads the next-stage payload from iCloud. Kaspersky also found a new Objective-C backdoor disguised as Finder that persists via LaunchAgent, .zshrc edits and global Git hooks.
- Commands are hidden in the DESCRIPTION: line of a public iCloud calendar event
- Backdoor disguises itself as Finder and kills macOS notifications
- Persistence via LaunchAgent, .zshrc and global Git hooks
- Stealer grabs passwords, cookies, wallet data, Telegram and Keychain
Read next
Security