Kaspersky finds MacSync: Mac infostealer delivered via iCloud calendar events
Kaspersky uncovered MacSync, a macOS infostealer delivered through fake apps that fetches instructions from public iCloud calendar events. The malware exfiltrates credentials, crypto wallets, Keychain, Telegram and SSH/AWS/Kubernetes/Git configs, while newer variants add an Objective-C backdoor spoofing Finder.
- Loader reads instructions from a public iCloud calendar event
- MacSync steals credentials, cookies, crypto wallets and Keychain data
- Newer variants add an Objective-C backdoor spoofing Finder
- Targets developers, crypto enthusiasts and IT users
Read next
Security