You probably use your calendar to keep track of appointments, birthdays and the occasional reminder you immediately snooze.
asserted
you → use → appointments
Hackers apparently see another possibility.
asserted
Hackers → see → possibility
Security researchers have uncovered a new version of MacSync malware that can use a public iCloud calendar event as part of its infection chain.
asserted
that → uncover → chain
Hidden inside the calendar data are commands that help download more malware onto a Mac.
asserted
that → hide → Mac
The calendar itself does not suddenly infect your computer because someone sent you an invitation.
asserted
someone → infect → invitation
The attack starts earlier, usually after someone downloads and runs a malicious app.
asserted
someone → start → app
Still, the iCloud trick shows how attackers can hide parts of an attack behind familiar services many of us trust.
asserted
many → show → us
Once MacSync gets inside, it can go after a lot more than your calendar.
asserted
it → get → calendar
Here's how MacSync works, what it can steal and the steps you can take to protect your Mac.
asserted
you → work → Mac
Watch the replay and discover 5 ways AI can help you get better healthcare.
asserted
you → watch → healthcare
Our free CyberGuy LIVE class Get Better Healthcare with AI has ended, but you can still watch the full replay.
asserted
you → get → replay
Kurt "CyberGuy" Knutsson walks you through five practical ways AI can help you prepare for appointments, remember important details, understand complicated medical information, research prescription questions and organize your next steps.
asserted
you → walk → steps
No technical experience is needed.
asserted
experience → need → ?
Plus, recordings of all our past classes are available, including How to Stop Spam, Phone Security and Financial Protection, each with a free downloadable checklist.
asserted
recordings → include → checklist
Watch the free replays and get your checklists at CyberGuyLive.com
What is MacSync malware?
MacSync is an information-stealing malware family targeting macOS.
asserted
MacSync → watch → macOS
Earlier versions shared similarities with the Atomic macOS Stealer, better known as AMOS.
asserted
versions → share → AMOS
Researchers say MacSync has since developed additional capabilities of its own.
asserted
MacSync → say → own
Kaspersky says the malware first appeared on the dark web in 2025 under the name Mac.c.
asserted
malware → say → name
Its creators later renamed it MacSync.
asserted
creators → rename → it
Researchers first spotted this newest version in the wild in September 2026.
asserted
Researchers → spot → September
MacSync operates under a malware-as-a-service model.
asserted
MacSync → operate → model
That means different criminals can use the malware while choosing their own methods for getting it onto someone's Mac.
asserted
criminals → mean → Mac
Attackers have previously spread MacSync through social engineering and ClickFix-style attacks, where a bogus message tells someone to copy and run a command.
asserted
message → spread → command
Criminals have also disguised it as free software, cracked applications and unfamiliar new apps.
asserted
Criminals → disguise → software
We've seen similar tricks before.
asserted
We → see → tricks
In one Mac campaign, fake CAPTCHA instructions convinced users to paste commands into Terminal, which then installed information-stealing malware.
asserted
which → convince → malware
How hackers can abuse iCloud calendars
Here's where this latest version gets particularly sneaky.
asserted
version → abuse → calendars
Kaspersky found one MacSync infection chain where a downloader connected to a public iCloud calendar.
asserted
downloader → find → calendar
Instead of using the calendar to schedule anything, the attackers placed malicious commands inside the event description.
asserted
attackers → use → description
The malware then feeds that calendar information into the Mac's zsh command-line shell.
asserted
malware → feed → shell
Most of the calendar text produces errors because the Mac does not recognize normal calendar information as commands.
asserted
Mac → produce → commands
However, when it reaches the malicious instructions placed after the event's description field, those commands can run.
asserted
commands → reach → field
They ultimately download a compressed archive from iCloud containing another malicious app.
asserted
They → download → app
That app then starts another stage of the infection.
asserted
app → start → infection
The attacker still needs to get malicious software running on the Mac first.
asserted
software → need → Mac
However, using Apple's infrastructure during the infection chain can make the activity look less suspicious.
asserted
activity → use → chain
Importantly, Kaspersky says at least one sample pointed to a public iCloud calendar.
asserted
sample → say → calendar
Other samples used attacker-controlled servers instead.
asserted
samples → use → servers
A fake crypto wallet helped spread MacSync
asserted
wallet → spread → MacSync
Researchers also found attackers disguising MacSync as a fake cryptocurrency wallet called Toria.
asserted
attackers → find → wallet
…and 90 more, not listed.