MacSync Malware Exploits Public iCloud Calendars to Deliver Native Payloads on macOS
New variant leverages covert calendar events to execute malicious code, researchers report

Key Takeaways
- A new MacSync malware variant targets macOS via public iCloud calendar events.
- Calendar events serve as a covert mechanism to deliver native malicious payloads.
- Technical details of the exploit chain are limited; full attack methodology unverified.
- No patches released; general security hygiene advised.
- Users should treat unexpected calendar events with suspicion and monitor system behavior.
Quick answers
- What happened?
- Security researchers have identified a new variant of the MacSync malware targeting macOS systems that uses public iCloud calendar events as a covert mechanism to deliver and execute native malicious payloads. The attack chain leverages calendar events to trigger code execution, though specific technical details of the delivery mechanism remain limited in initial reporting.
- Which products are affected?
- MacSync
- What should defenders do?
- Update macOS to the latest version. Avoid interacting with suspicious or unexpected calendar events. Monitor for anomalous process behavior and unauthorized network connections. Apply standard endpoint security best practices.
A new variant of the MacSync malware has been observed targeting macOS systems by abusing public iCloud calendar events. According to reporting, the malware uses calendar events as a delivery mechanism to drop and execute native payloads on affected systems. The exact technical chain—including how calendar events trigger execution, the method of persistence, and the specific capabilities of the deployed payloads—has not been fully detailed in the initial reports. The use of public iCloud calendars represents a covert command-and-control or delivery channel that may evade traditional network-based defenses. No specific vendor advisories or patches have been issued at this time. Security experts recommend updating macOS to the latest version, avoiding interaction with suspicious calendar events, and monitoring for anomalous process behavior as provisional mitigations.
Security Details
The MacSync malware variant leverages public iCloud calendar events to deliver native payloads to macOS systems. The method by which calendar events trigger execution and the full capabilities of the deployed payloads are not fully detailed in current reporting. The use of public calendar services as a delivery mechanism represents a novel approach to evading traditional network defenses.
Affected products
MacSync
Mitigation
Update macOS to the latest version. Avoid interacting with suspicious or unexpected calendar events. Monitor for anomalous process behavior and unauthorized network connections. Apply standard endpoint security best practices.
Sources
BleepingComputer
MacSync malware uses public iCloud calendars to deliver new payloads
Sep 24, 2026 · 20:53
Original link
Related Security News

Star Blizzard Campaign Targets 100+ Organizations with Fake Event Invitations
Microsoft reports that the Russian state-sponsored threat actor Star Blizzard has been conducting a sustained campaign since January 2026, using fake event invitations to trick targets into installing a backdoor on Windows computers. The operation has affected more than 100 organizations, primarily in the U.S. and U.K., with victims tied to Ukraine. At least one infection has been confirmed, though the full extent of breaches and data exfiltration remains unverified.




