MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-25 · via Help Net Security

Mac malware abuses iCloud calendar to deliver infostealer payload

Image via Help Net Security
Image via Help Net Security

Kaspersky found a new MacSync variant being spread through a fake crypto wallet app called Toria, which was promoted on X and Telegram. The malware includes infostealer and backdoor capabilities aimed at credentials, crypto wallet data, and files. The latest version uses Swift and Objective-C executables, binary droppers and loaders, and in one delivery chain hides malicious commands in a public iCloud calendar file that is fed into zsh.

Expanded Detail

MacSync first appeared in 2025 under the name Mac.c before being rebranded. Its initial variants relied on AppleScripts similar to those used by AMOS, and later builds gained a backdoor component. Kaspersky observed the newest build in September 2026.

This iteration shifts to compiled Swift and Objective-C payloads, with binary droppers and loaders. In one infection path, a public iCloud calendar file is read line by line into zsh; harmless lines fail until commands placed after DESCRIPTION execute. The fake wallet Toria was promoted on X and Telegram.

Context

Mac users, especially those handling cryptocurrency or sensitive credentials, could face stolen logins, wallet data, and files if they install the fake Toria app. Because the malware may persist and request administrator privileges, victims could lose access to accounts or assets, and organizations with Mac fleets might need to review endpoint controls and user awareness. The use of trusted cloud services for delivery may make detection harder, potentially increasing the reach of such campaigns.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at Help Net Security →
Related stories
PamStealer Update Uses Server-Side Decryption and Layered Persistence on macOS · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “MacSync info-stealing malware hides malicious commands in an iCloud calendar.” Browse more stories.