← Back to feed
Threat Actors & CampaignsEmerging1 sourceSep 25, 2026 · 09:22via Help Net Security

MacSync info-stealing malware hides malicious commands in an iCloud calendar

Brief

A new MacSync variant targets Mac users with an infostealer and persistent backdoor designed to steal credentials, crypto wallet data, and files, according to Kaspersky. Researchers found the malware spreading through a crypto wallet app called Toria, which had its own website and was promoted on X and Telegram. MacSync is a family of Mac malware that emerged in 2025 as Mac. c and was later renamed.

Early versions used AppleScripts that closely resembled the AMOS … More →

The post MacSync info-stealing malware hides malicious commands in an iCloud calendar appeared first on Help Net Security .

Read more on Help Net Security→