MacSync Malware Uses iCloud Calendar to Steal Data from Mac Users
Baca dalam 60 detik
- Kaspersky menemukan MacSync, infostealer yang menyusup lewat event kalender iCloud dan aplikasi palsu.
- Malware ini menargetkan kredensial, dompet kripto, dan data pengembang, dengan backdoor yang menyamar sebagai Finder.
- Pengguna Mac diimbau waspada mengunduh perangkat lunak dari sumber tidak resmi dan tidak memberikan kata sandi admin sembarangan.

Cybersecurity researchers from Kaspersky have uncovered a new malware campaign targeting Mac users through an unexpected gap: iCloud calendar events. The malware, named MacSync, spreads through fake apps and pirated software, then steals various sensitive data from victims' devices.
MacSync first appeared in April 2025 and is a derivative of AMOS, one of the popular infostealers for macOS. Since then, the malware has evolved rapidly with increasingly sophisticated capabilities. Kaspersky noted that the latest variant has an Objective-C-based backdoor that disguises itself as Finder, macOS's built-in file manager, to evade detection.
MacSync's modus operandi is fairly innovative. After being downloaded and executed, the malware loader accesses the iCloud calendar and looks for public events that have been prepared by the attacker. In the event description, there are instructions and the location of the infostealer to be downloaded. This calendar access activity looks normal, so it is unlikely to raise suspicion. Next, the infostealer is downloaded from iCloud storage and executed to compromise the target device.
According to Kaspersky, MacSync is distributed through social media, SEO poisoning, and phishing. Victims are directed to fake websites or social media channels promoting pirated software or free versions of paid solutions. In one example, the loader was advertised as a cryptocurrency wallet. The victim then sees a ClickFix error message and is asked to fix it by pasting a command into Terminal. That command downloads the loader and installs MacSync.
"The nature of the data the attackers want to collect from victims' devices, as well as the categories of applications this stealer disguises itself as, clearly show that this malware family primarily targets developers, crypto enthusiasts, and other users associated with IT and the crypto space," a Kaspersky researcher stated. "Compromise of software developers' devices poses a particular security risk to end users and corporate systems, opening greater opportunities for attackers to conduct further intrusions."
This attack highlights a rarely noticed security gap in the Apple ecosystem. Although macOS is known to be more secure than Windows, malware that exploits cloud services like iCloud calendar shows that attackers continue to innovate in search of gaps. Mac users in Indonesia, especially developers and those in the crypto industry, need to increase their vigilance. Downloading software from unofficial sources or following unclear error-fix instructions can become a gateway for malware.
Kaspersky recommends that users not easily trust apps that ask for admin passwords, always verify download sources, and use reliable security solutions. The company has also released a list of indicators of compromise (IoC) to help with early detection. With increasingly sophisticated attack techniques, collaboration between security researchers, developers, and users is key to breaking the infection chain.
Going forward, the question is how far Apple will tighten the security of its cloud services, and whether Mac users will change their app-downloading habits to protect their personal and business data.



