Find notable cyber news and cases, enriched with sources, timelines, and signals.

MacSync macOS infostealer with iCloud calendar payload delivery

Malware Activity
First reported
Last updated
Happening score
H score 29
1 unique sources, 1 articles

Summary

Hide ▲

MacSync now uses public iCloud calendar events to deliver fresh payloads on macOS, expanding its infection chain and increasing the risk of credential theft and remote control. The malware also adds a new Objective-C backdoor that can run attacker-supplied AppleScript, establish persistence, and upload files to command-and-control infrastructure. Its distribution has included ClickFix-style attacks and fake software lures, including a fake crypto wallet called Toria.

Related Happenings

PasteSwitch malicious ClickFix ads campaign via HBO Max Reddit account

Campaign
H score32 First: 21.09.2026 11:39 Last: 21.09.2026 11:39 Sources 1

About this happening: The PasteSwitch campaign abused HBO Max's official Reddit account (u/hbomax) to push 108 malicious ads over 48 hours, turning a trusted brand channel into a delive...

PasteSwitch ClickFix malware delivery of MacSync, AMOS helper, and Amatera Stealer

Malware Activity
H score30 First: 14.09.2026 21:34 Last: 14.09.2026 21:34 Sources 1

How related: MacSync has been distributed to victims through social engineering, including ClickFix-style attacks, and through software presented as free, cracked, or as new applications.

About this happening: PasteSwitch continues to use ClickFix-style social engineering to push MacSync and related payloads onto Windows and macOS systems, with a prior HBO Max Re...

Latest development: 24.09.2026 23:53

Kaspersky identified a MacSync campaign targeting macOS that uses public iCloud calendar events to hide commands in the DESCRIPTION: line, fetch a next-stage archive from iCloud, and reach the malware through an APP bundle dropper. The same campaign also adds an Objective-C backdoor that disguises itself as Finder, establishes persistence through LaunchAgent, .zshrc modifications, and global Git hooks, and can run attacker-supplied AppleScript or replace an installed Ledger wallet app.

Fake Codex download campaign using Google Sites and ClickFix

Campaign
H score35 First: 24.08.2026 18:00 Last: 24.08.2026 18:00 Sources 1

About this happening: The fake Codex download campaign is using sponsored search results, Google Sites lures, and ClickFix instructions to push macOS users into running malware. The...

ClickFix AmnesiaStealer distribution campaign targeting mac users

Campaign
H score22 First: 14.08.2026 13:45 Last: 14.08.2026 13:45 Sources 1

About this happening: A ClickFix campaign is distributing AmnesiaStealer to macOS users through a counterfeit GitHub "Download for macOS" page and a copy-and-paste command that launches...

Latest development: 16.08.2026 18:07

Jamf described AmnesiaStealer's stream_module and remote_stream commands, which copy a victim's Chromium profile into a hidden headless browser and open WebSocket and Chrome DevTools Protocol channels through webSocketDebuggerUrl. The operator can issue navigation and mouse commands, receive live screencasts, and export or import cookies to operate online portals inside the victim's authenticated sessions on Google Chrome, Microsoft Edge, Vivaldi, Arc, Opera, Brave, and Chromium.

AmnesiaStealer macOS infostealer distributed via ClickFix

Malware Activity
H score16 First: 14.08.2026 13:45 Last: 14.08.2026 13:45 Sources 1

About this happening: AmnesiaStealer is a Rust-based macOS infostealer spread through a counterfeit GitHub "Download for macOS" page and ClickFix-style lure. It steals Keychain, b...

Timeline

  1. 24.09.2026 23:53 2 articles · 2h ago

    MacSync uses public iCloud calendar events to deliver payloads

    Initial Disclosure

    Kaspersky describes a new MacSync variant targeting macOS that uses public iCloud calendar events to fetch fresh payloads, with a downloader reading commands from a calendar event’s DESCRIPTION line, retrieving an archive from iCloud, and unpacking an APP bundle dropper. The campaign also adds an Objective-C backdoor that disguises itself as Finder, persists through LaunchAgent, .zshrc modifications, and global Git hooks, can run attacker-supplied AppleScript, and can replace an installed Ledger wallet app.

    Show sources