stealing malware hides malicious commands in an iCloud calendar

MacSync info-stealing malware hides malicious commands in an iCloud calendar A new MacSync variant targets Mac users with an infostealer and persistent backdoor designed to steal credentials, crypto wallet data, and files, according to Kaspersky.
Researchers found the malware spreading through a crypto wallet app called Toria, which had its own website and was promoted on X and Telegram.
MacSync is a family of Mac malware that emerged in 2025 as Mac.c and was later renamed. Early versions used AppleScripts that closely resembled the AMOS stealer, while newer variants added a backdoor module. Kaspersky first spotted the latest version in September 2026.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in