{"id":244476,"date":"2026-09-25T01:22:15","date_gmt":"2026-09-25T06:22:15","guid":{"rendered":"https:\/\/lifeboat.com\/blog\/2026\/09\/macsync-malware-uses-public-icloud-calendars-to-deliver-new-payloads"},"modified":"2026-09-25T01:22:15","modified_gmt":"2026-09-25T06:22:15","slug":"macsync-malware-uses-public-icloud-calendars-to-deliver-new-payloads","status":"publish","type":"post","link":"https:\/\/lifeboat.com\/blog\/2026\/09\/macsync-malware-uses-public-icloud-calendars-to-deliver-new-payloads","title":{"rendered":"MacSync malware uses public iCloud calendars to deliver new payloads"},"content":{"rendered":"<p><a class=\"aligncenter blog-photo\" href=\"https:\/\/lifeboat.com\/blog.images\/macsync-malware-uses-public-icloud-calendars-to-deliver-new-payloads.jpg\"><\/a><\/p>\n<p>A new variant of the MacSync info-stealing malware targeting macOS systems now uses public iCloud calendar events to deliver fresh payloads.<\/p>\n<p>MacSync is a Swift-based malware that emerged in April 2025 and has been observed recently being delivered in <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/claude-llm-artifacts-abused-to-push-mac-infostealers-in-clickfix-attack\/\" rel=\"nofollow noopener\" target=\"_blank\">ClickFix campaigns<\/a> disguised as Homebrew and macOS disk space analyzer tools.<\/p>\n<p>Kaspersky researchers say that while earlier versions of the malware were derived from the AMOS stealer family, MacSync evolved and added new capabilities via modules.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A new variant of the MacSync info-stealing malware targeting macOS systems now uses public iCloud calendar events to deliver fresh payloads. MacSync is a Swift-based malware that emerged in April 2025 and has been observed recently being delivered in ClickFix campaigns disguised as Homebrew and macOS disk space analyzer tools. Kaspersky researchers say that while [\u2026]<\/p>\n","protected":false},"author":427,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[34,8],"tags":[],"class_list":["post-244476","post","type-post","status-publish","format-standard","hentry","category-cybercrime-malcode","category-space"],"_links":{"self":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/244476","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/users\/427"}],"replies":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/comments?post=244476"}],"version-history":[{"count":0,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/244476\/revisions"}],"wp:attachment":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/media?parent=244476"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/categories?post=244476"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/tags?post=244476"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}