MacSync Malware Uses Public iCloud Calendars to Deliver New Payloads

Executive Summary

A new variant of the MacSync malware, which targets macOS, now exploits public iCloud calendar events to deliver native payloads. Attackers embed malicious links or code in calendar entries that, when opened by users, trigger the download and execution of additional malware components. The technique expands the malware’s distribution vector beyond traditional phishing or drive‑by sites, increasing the risk for Mac users who share or view public calendars.


Intelligence Metadata - Source Publisher: Bleeping Computer - Published Date: 2026-09-24T20:53:35+00:00 - Category: threat-intel

Original Description: A new variant of the MacSync malware targeting macOS systems now uses public iCloud calendar events to deliver new native payloads. [...]

"Our kindness may be the most persuasive argument for that which we believe."

— Gordon Hinckley
Source: Bleeping Computer