Urgent.News

What's breaking now, across thousands of outlets.

Tech

This Mac malware is somehow using iCloud calendar invites to try and steal your data

A loader talks to iCloud before deploying a sophisticated infostealer and stealing all your cryptos.

This Mac malware is somehow using iCloud calendar invites to try and steal your data

A new Mac malware, called MacSync, is using iCloud calendar events to deliver a powerful infostealer to Mac devices. Security researchers Kaspersky uncovered the malware, which is hidden behind fake cryptocurrency wallets and cracked commercial software. The loader fetches instructions from calendar entries, then deploys the malware, exfiltrating credentials, wallets, and developer data.

MacSync was first seen in April 2025 and is based on Swift. It can now exfiltrate additional data, including browser history, cookies, saved credentials, cryptocurrency wallet data, Telegram data, Keychain data, system and device information, and even SSH, AWS, Kubernetes, Git, and shell configuration files. The malware also includes an Objective-C backdoor that spoofs the macOS Finder and grants attackers persistent access.

Kaspersky advises Mac users to be cautious when downloading software, especially from third-party websites, and to question apps that ask for admin passwords.

Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at techradar.com →

More in Tech

More from Friday 25 September →