Help Net Security·4 min read

stealing malware hides malicious commands in an iCloud calendar

S
Sinisa Markovic
stealing malware hides malicious commands in an iCloud calendar
✦Dive DeeperCreate a free account to unlock

MacSync info-stealing malware hides malicious commands in an iCloud calendar A new MacSync variant targets Mac users with an infostealer and persistent backdoor designed to steal credentials, crypto wallet data, and files, according to Kaspersky.

Researchers found the malware spreading through a crypto wallet app called Toria, which had its own website and was promoted on X and Telegram.

MacSync is a family of Mac malware that emerged in 2025 as Mac.c and was later renamed. Early versions used AppleScripts that closely resembled the AMOS stealer, while newer variants added a backdoor module. Kaspersky first spotted the latest version in September 2026.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
✦

Get smarter about the news

Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.

Create free account

Already have an account? Sign in