MacSync malware hides commands in iCloud calendar, warns users
A new variant of the MacSync malware family has been found embedding malicious commands in an iCloud calendar entry, allowing it to steal credentials, cryptocurrency wallet data and personal files from macOS computers. Kaspersky researchers traced the infection to a cryptocurrency wallet application called Toria, which was promoted on X and Telegram before being distributed to unsuspecting users.
The threat primarily affects Mac users who download and install the Toria wallet app from its unofficial website. Once installed, the malware creates a hidden calendar event in the victim’s iCloud account. The event contains encoded instructions that the malware reads and executes, establishing a persistent backdoor on the system. This backdoor enables the theft of saved passwords, browser data, cryptocurrency wallet files and other sensitive information. Because the commands are stored in a legitimate iCloud calendar, they are difficult for standard antivirus tools to detect.
Kaspersky’s analysis confirms that the malicious code is not a simple script but a compiled infostealer that runs silently in the background. The attackers use the iCloud calendar as a covert communication channel, periodically updating the hidden event with new commands. This method bypasses many traditional security checks that focus on file-based malware.
Mac users can reduce the risk by avoiding the download of cryptocurrency wallet software from unverified sources. If the Toria app has already been installed, users should uninstall it immediately and run a thorough scan with a reputable security tool. ComputerScams.com offers a free macOS malware scanner that can help detect hidden threats. Additionally, checking iCloud calendar entries for unknown or suspicious events and removing any that appear unfamiliar can close the hidden channel the malware uses.
To protect against similar attacks, enable two‑factor authentication on iCloud and other critical accounts, keep macOS and all applications up to date, and use strong, unique passwords stored in a trusted password manager. Regularly reviewing account activity and disabling calendar syncing for applications that do not require it adds another layer of defense.
A practical step you can take right now is to open your iCloud calendar on a web browser, look for any events you do not recognize, and delete them. This simple action can cut off the malware’s command channel and limit further data loss.
Source: Read the original report