A newly identified version of the MacSync malware is using a more complex infection chain that can involve files hosted through public iCloud Calendar entries, adding another layer to a growing campaign targeting cryptocurrency users on macOS.
Kaspersky disclosed the updated MacSync variant on September 17, saying researchers detected the new version in September 2026. MacSync originally emerged in 2024 and 2025 as a derivative of Atomic macOS Stealer, or AMOS, but the latest build has expanded beyond a conventional information-stealing program.
The new infection chain installs two main components on a victim’s Mac: an infostealer designed to collect credentials and sensitive data, and a backdoor that allows attackers to retain remote access to the compromised system.
The initial infection can begin when a user downloads malware disguised as legitimate software, including document-sharing applications or cryptocurrency wallet applications. Kaspersky said that in some observed cases, one of the malicious downloads used later in the attack chain was hosted within a publicly accessible iCloud Calendar entry in .ics format.
That detail makes the campaign unusual. Rather than relying exclusively on attacker-controlled websites and domains, part of the delivery process can use infrastructure associated with Apple’s iCloud service. Kaspersky has not publicly disclosed the affected calendar URLs, the number of victims identified in the campaign or whether the relevant public calendar objects remain accessible.
Once the infostealer launches, it presents itself as the application the victim believed they had downloaded and asks for the macOS administrator password. After the password is entered, the malware displays a message claiming that the application is damaged and should be moved to the bin.
Behind that distraction, MacSync can collect browser history, cookies, stored credentials, cryptocurrency-wallet information, Telegram data, device login credentials and the macOS Keychain file. It also gathers details about installed applications, hardware, device models and SSH and ZSH configurations.
The scope of collection reflects a broader problem for users of self-custody wallets. Moving crypto away from centralized exchanges removes one form of counterparty risk, but control of the assets ultimately still depends on the security of the device, wallet software and credentials used to manage them.
MacSync’s second component increases that risk further. Kaspersky said the backdoor disguises itself as Apple’s Finder application and can give attackers continuing access to the device. Attackers can use it to deploy modified browser add-ons, potentially replacing legitimate cryptocurrency wallet extensions with malicious versions.
The backdoor can also replace the legitimate Ledger wallet application with a malicious clone, retrieve selected files and system information and potentially execute additional code. Earlier research into MacSync has also documented interest in Ledger and Trezor-related applications, highlighting how wallet software vulnerabilities and endpoint compromise can become direct financial risks rather than ordinary IT-security problems.
Microsoft had already documented MacSync activity before Kaspersky’s latest discovery. In August, Microsoft Defender researchers said they connected more than 30 domains to rotating MacSync infrastructure by following repeated network and execution patterns rather than individual domains.
Microsoft observed MacSync using Terminal sessions, curl, AppleScript and native macOS utilities to retrieve payloads, collect data and upload stolen information. The malware targeted browser credentials, cookies, session data, Keychain material, SSH keys, cloud credentials and files stored in common user directories.
That campaign showed why static domain blocking alone may struggle against malware that continuously changes its infrastructure. Similar social-engineering attacks across the crypto industry have repeatedly demonstrated that obtaining one sensitive credential or compromising one trusted device can provide attackers with a route toward wallets or other financial systems.
Apple has already moved to strengthen macOS against some of the techniques commonly used by MacSync and AMOS campaigns. Beginning with macOS 26.4, Apple introduced Terminal paste protections designed to warn users when commands copied from browsers, messaging applications and other common attack sources are pasted into Terminal.
XProtect can also inspect processes triggered by pasted commands, while Apple’s scripting protections scan AppleScript and JavaScript for Automation activity for known malicious behavior. Those defenses are particularly relevant because Microsoft has observed MacSync using AppleScript-assisted execution and Terminal-based delivery.
The new iCloud Calendar technique, however, shows that attackers are continuing to experiment with additional delivery infrastructure. It follows a year in which crypto security incidents have increasingly involved weaknesses outside the blockchain itself, including endpoints, internal systems, authentication infrastructure and user devices.
Why the iCloud Calendar Technique Matters
The most important part of this MacSync update is not that another piece of malware can steal cryptocurrency. That problem is already well established.
What matters is the infrastructure attackers are beginning to use.
Security teams are good at blocking malicious domains once they are identified. Attackers respond by rotating those domains faster. Microsoft saw exactly that pattern with MacSync, where more than 30 related domains could be connected through behavior even while the infrastructure itself kept changing.
Putting part of an infection chain inside a public iCloud Calendar object changes the equation slightly. An Apple-hosted resource carries very different infrastructure characteristics from an obviously disposable malware domain. Blocking an entire trusted cloud service would create enormous collateral damage, which means defenders have to evaluate the content and behavior around the request rather than simply blacklist the host.
This is not entirely new as an attacker strategy. Criminal groups have repeatedly abused legitimate cloud services, code repositories and collaboration platforms because trusted infrastructure creates friction for defenders. The MacSync example matters because it brings that model directly into malware designed around high-value crypto theft.
For crypto holders, the threat also exposes a weakness in the idea that hardware wallets automatically isolate funds from compromised computers. Private keys can remain protected while the software surrounding them is manipulated. If malware replaces a wallet application, modifies a browser extension or presents a convincing seed-phrase recovery prompt, the attacker may not need to break the hardware device at all.
That distinction matters after recent cases involving unauthorized transfers from personal wallets and larger crypto infrastructure breaches. The attack surface increasingly includes every layer between the user and the blockchain.
There is also a persistence problem. A one-time infostealer typically collects information and sends it away. A backdoor that remains on the Mac gives attackers more options. They can observe what software is installed, wait for a valuable wallet to appear, replace components later or deliver new payloads after the initial compromise.
That means removing the original fake application may not be enough if the broader infection succeeded.
The next useful disclosures from Kaspersky will therefore be highly technical: which wallet extensions the current build targets, which applications can be replaced, how persistence is established, what indicators defenders can monitor and whether the public iCloud Calendar artifacts have been disabled.
Apple’s recent Terminal and AppleScript protections raise the cost of older MacSync delivery methods, but the September variant suggests the malware’s developers are adapting quickly. For investors and crypto users, the practical lesson is increasingly clear: self-custody protects against an intermediary losing control of the assets, but it does not remove endpoint risk. As more value moves into wallets controlled directly by users, the Mac itself becomes part of the custody infrastructure.
Michael Lebowitz is a financial markets analyst and digital finance writer specializing in cryptocurrencies, blockchain ecosystems, prediction markets, and emerging fintech platforms. He began his career as a forex and equities trader, developing a deep understanding of market dynamics, risk cycles, and capital flows across traditional financial markets.
In 2013, Michael transitioned his focus to cryptocurrencies, recognizing early the structural similarities—and critical differences—between legacy markets and blockchain-based financial systems. Since then, his work has concentrated on crypto-native market behavior, including memecoin cycles, on-chain activity, liquidity mechanics, and the role of prediction markets in pricing political, economic, and technological outcomes.
Alongside digital assets, Michael continues to follow developments in online trading and financial technology, particularly where traditional market infrastructure intersects with decentralized systems. His analysis emphasizes incentive design, trader psychology, and market structure rather than short-term price action, helping readers better understand how speculative narratives form, evolve, and unwind in fast-moving crypto markets.

