Mac malware can hide commands in your iCloud calendar

Mac malware can hide commands in your iCloud calendar

Mac malware can hide commands in your iCloud calendar

You probably use your calendar to keep track of appointments, birthdays and the occasional reminder you immediately snooze. Hackers apparently see another possibility. Security researchers have uncovered a new version of MacSync malware that can use a public iCloud calendar event as part of its infection chain. Hidden inside the calendar data are commands that help download more malware onto a Mac.


The calendar itself does not suddenly infect your computer because someone sent you an invitation. The attack starts earlier, usually after someone downloads and runs a malicious app. Still, the iCloud trick shows how attackers can hide parts of an attack behind familiar services many of us trust. Once MacSync gets inside, it can go after a lot more than your calendar. Here's how MacSync works, what it can steal and the steps you can take to protect your Mac.


Missed CyberGuy LIVE? Watch the replay and discover 5 ways AI can help you get better healthcare.


Our free CyberGuy LIVE class Get Better Healthcare with AI has ended, but you can still watch the full replay. Kurt "CyberGuy" Knutsson walks you through five practical ways AI can help you prepare for appointments, remember important details, understand complicated medical information, research prescription questions and organize your next steps. No technical experience is needed.


Plus, recordings of all our past classes are available, including How to Stop Spam, Phone Security and Financial Protection, each with a free downloadable checklist.


Watch the free replays and get your checklists at CyberGuyLive.com


THOUSANDS OF HACKED SITES TRICK YOU INTO INSTALLING MALWARE


MacSync is an information-stealing malware family targeting macOS. Earlier versions shared similarities with the Atomic macOS Stealer, better known as AMOS. Researchers say MacSync has since developed additional capabilities of its own. Kaspersky says the malware first appeared on the dark web in 2025 under the name Mac.c. Its creators later renamed it MacSync. Researchers first spotted this newest version in the wild in September 2026.


MacSync operates under a malware-as-a-service model. That means different criminals can use the malware while choosing their own methods for getting it onto someone's Mac. Attackers have previously spread MacSync through social engineering and ClickFix-style attacks, where a bogus message tells someone to copy and run a command. Criminals have also disguised it as free software, cracked applications and unfamiliar new apps. We've seen similar tricks before. In one Mac campaign, instructions convinced users to paste commands into Terminal, which then installed information-stealing malware.


Here's where this latest version gets particularly sneaky. Kaspersky found one MacSync infection chain where a downloader connected to a public iCloud calendar. Instead of using the calendar to schedule anything, the attackers placed malicious commands inside the event description. The malware then feeds that calendar information into the Mac's zsh command-line shell.


FAKE CHROME UPDATE SCAM COULD INFECT YOUR COMPUTER


Most of the calendar text produces errors because the Mac does not recognize normal calendar information as commands. However, when it reaches the malicious instructions placed after the event's description field, those commands can run. They ultimately download a compressed archive from iCloud containing another malicious app. That app then starts another stage of the infection.


Think of the calen

  • Share on:

Weather

Woodland Heights

22c
Cloudy

Humidity: 57%

NEAir8.3Kph

  • 20.7c
    20
  • 19.7c
    21
  • 19c
    22
  • 18.4c
    23
image title here

Some title