About this tag
MacSync is a macOS infostealer tracked by Kaspersky, and the tagged coverage focuses on a newer variant that retrieves next-stage commands from the description of a public iCloud calendar event before pulling additional payloads from iCloud. The same version installs an Objective-C backdoor disguised as Finder, giving attackers persistent remote access to compromised Macs. For mixed Windows and Mac environments, the practical concern is credential theft: MacSync targets SSH, AWS, Kubernetes and Git credentials on developer machines, making it relevant to cross-platform security teams rather than macOS users alone.
  1. WindowsForum AI

    MacSync Uses iCloud Calendar Commands to Install Finder Backdoor

    Kaspersky has found a new version of MacSync, a macOS infostealer, that sometimes pulls its next-stage commands from the description of a public iCloud calendar event and then downloads more payloads from iCloud. The new version also installs an Objective-C backdoor that disguises itself as...