MacSync (Mac.c) macOS Info-Stealer Abuses Public iCloud Calendars as C2 Dead-Drop in Fake "Toria" Crypto Wallet Campaign

MacSync (Mac.c) macOS Info-Stealer Abuses Public iCloud (TL-2026-2723), also tracked as Mac.c, is a high-severity malware campaign, first published 2026-09-27. It has no confirmed attribution, affects Apple macOS, maps to 17 MITRE ATT&CK techniques (T1005, T1027, T1036.005), and is covered by 9 detection rules and 26 indicators of compromise.

Key facts for TL-2026-2723

Threat ID
TL-2026-2723
Also known as
Mac.c
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-09-27
Last reviewed
2026-09-27
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
technology, cryptocurrency
Detection rules
9
Indicators of compromise
26

Malware and tooling in MacSync (Mac.c) macOS Info-Stealer Abuses Public iCloud

Malware and tooling: MacSync, Toria, http://caldav.icloud.com/published/2/MTk1NDMwMDMzNTUxOTU0M1aHCZ-nMxiyGzBTzPiodOf44DtKJ6PpjftAG28_ui2NCYMpL_vu4pF4ddsJ8ysg0QI7pR0VEIEbZYdilVZRw08

Kaspersky (researcher Sergey Puzan) identified a new version of the MacSync (aka Mac.c) macOS infostealer distributed via a fake cryptocurrency wallet app named Toria, promoted on X and Telegram. The malware's six-stage infection chain hides a downloader link inside a public iCloud calendar event and ultimately deploys a Swift/Objective-C infostealer and a Finder-disguised backdoor that harvest browser, crypto-wallet, Keychain, SSH/AWS/Kubernetes/Git, and Telegram data.

How MacSync (Mac.c) macOS Info-Stealer Abuses Public iCloud works

MacSync, first observed in 2025 under the name Mac.c as an AppleScript-based stealer resembling the AMOS (Atomic macOS Stealer) family, resurfaced in September 2026 with a substantially reworked, compiled Swift/Objective-C payload and a novel command-delivery mechanism. The current campaign lures victims -- primarily macOS developers, IT-associated users, and cryptocurrency holders -- with a fake wallet application called "Toria," advertised via a dedicated website (toria.app) and promoted through X and Telegram accounts.

The infection begins with a malicious DMG containing a compiled JXA loader that strips the macOS quarantine attribute (xattr -cr) and decodes an XOR-encrypted (key 73 6f 6e 6f 6d 61 62 6c 64 07) downloader URL. That URL points to a public iCloud CalDAV calendar (caldav.icloud[.]com/published/2/...); the loader fetches the calendar's raw text and pipes it to zsh. Most of the calendar body is inert text that produces shell errors, but the malware places live commands immediately after the event's DESCRIPTION: field, which zsh executes -- a dead-drop technique that abuses a legitimate Apple sharing feature and leaves no attacker-controlled infrastructure in the initial fetch. Those commands retrieve an AES-CBC-encrypted TAR.GZ (first dropper), which in turn unpacks a second dropper that performs VM detection (sysctl kern.hv_vmm_present, machdep.cpu.brand_string) and sets PT_DENY_ATTACH to block debuggers before decrypting and executing a fifth-stage script. That script downloads the final infostealer and backdoor modules using a custom pkgunpack utility implementing Curve25519 ECDH key exchange and AES-GCM decryption.

The backdoor persists via a LaunchAgent labeled com.apple.finder.agent (masquerading as Finder), a .zshrc modification that runs a hidden .repair-run recovery script, and global git pre-commit/post-checkout hooks. The .repair-run script restores backdoor files from a backup at $HOME/Library/Application Support/System if they are removed, and kills BTMNotificationAgent, NotificationCenter, and BackgroundTaskManagementAgent to suppress macOS's background-task notifications. The backdoor exposes AppleScript-wrapped commands including deploy_ext (malicious browser extension installation), deploy_ledger (Ledger hardware-wallet software replacement), regrab (re-collects host data into /tmp/osalogging.zip), and live_browser (an adversary-in-the-middle traffic interceptor via an sn_relay component).

The infostealer module harvests browser history, cookies, saved credentials and Safe Storage keys (Chrome, Brave), cryptocurrency wallet extension/app data, Telegram files, the Keychain file, SSH/zsh/AWS/Kubernetes/Git configuration files, shell command history, and system/process/application inventory. Collected data is uploaded to the C2 over authenticated PUT requests (custom X-Upload-Token header) in 90-megabyte chunks via a documented REST API (GET /v1/agent/ping, POST /v1/agent/refresh, POST /v1/asset/<id>/init, PUT /v1/asset/<id>). C2 and staging infrastructure impersonates well-known brands (Apple App Store, Slack, StreamYard) under domains such as toria.apple03cloudstore[.]com, docsend.appstore[.]com[.]mx, streamyard.appstore[.]com[.]mx, slack.apple03cloudstore[.]com, and waaako.appstore[.]com[.]mx.

MITRE ATT&CK techniques used in TL-2026-2723

Collection

T1005 Data from Local System; T1074.001 Data Staged: Local Data Staging; T1557 Adversary-in-the-Middle

Defense Evasion

T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1497.001 Virtualization/Sandbox Evasion: System Checks; T1622 Debugger Evasion

Persistence

T1176 Software Extensions; T1543.001 Create or Modify System Process: Launch Agent; T1546.004 Event Triggered Execution: Unix Shell Configuration Modification

Execution

T1204.002 User Execution: Malicious File

Credential Access

T1539 Steal Web Session Cookie; T1552.001 Unsecured Credentials: Credentials In Files; T1555.001 Credentials from Password Stores: Keychain

defense-impairment

T1553.001 Subvert Trust Controls: Gatekeeper Bypass; T1685 Disable or Modify Tools

Resource Development

T1583.001 Acquire Infrastructure: Domains

Affected products and versions in MacSync (Mac.c) macOS Info-Stealer Abuses Public iCloud

  • Apple — macOS
    Vulnerable versions: All supported macOS versions (delivered via trojanized application and social engineering, not a software vulnerability)

Remediation for MacSync (Mac.c) macOS Info-Stealer Abuses Public iCloud

Patches

  • No vendor patch applies; MacSync is delivered via social engineering and a trojanized application, not a software vulnerability.

Immediate actions

  • Block the identified C2 and staging domains/URLs (toria.app, toria.apple03cloudstore.com, docsend.appstore.com.mx, streamyard.appstore.com.mx, slack.apple03cloudstore.com, waaako.appstore.com.mx, warpcast.asia) at DNS/proxy/firewall.
  • Hunt for and remove the com.apple.finder.agent LaunchAgent, .zshrc modifications referencing a .repair-run script, and global git pre-commit/post-checkout hooks on macOS endpoints.
  • On any confirmed-infected host, rotate SSH keys, AWS credentials, Kubernetes kubeconfigs, Git credentials/tokens, browser-saved passwords, and Keychain-protected secrets, and revoke active browser session cookies.
  • Inspect and remove any unauthorized browser extensions and check for Ledger/hardware-wallet software tampering on affected hosts.

Workarounds

  • Do not download or run cryptocurrency wallet applications advertised via X/Telegram links; verify publisher identity and obtain wallet software only from official vendor sites or the Mac App Store.
  • Restrict or monitor use of public/shared iCloud calendar subscriptions on managed macOS fleets.

Longer-term hardening

  • Deploy EDR/behavioral monitoring on macOS fleets for zsh processes spawned from curl/network fetches to iCloud/CalDAV endpoints, xattr -cr invocations, and PT_DENY_ATTACH/anti-VM syscall patterns.
  • Monitor outbound HTTP PUT requests with custom auth headers (e.g., X-Upload-Token) and large (~90MB) chunked uploads to unrecognized domains.
  • Enforce application allow-listing / Gatekeeper notarization checks and alert on DMG installations that strip quarantine attributes shortly after download.
  • Educate developer and crypto-holding staff on the risk of installing wallet/crypto apps from social-media-promoted links rather than official app stores or vendor sites.

Timeline of MacSync (Mac.c) macOS Info-Stealer Abuses Public iCloud

  • MacSync first emerges under the name Mac.c as an AppleScript-based macOS infostealer resembling the AMOS (Atomic macOS Stealer) family.
  • Kaspersky researcher Sergey Puzan identifies a reworked MacSync variant using a public iCloud calendar as a C2 dead-drop and compiled Swift/Objective-C infostealer and backdoor payloads.
  • Kaspersky publishes the technical analysis "A new version of the MacSync macOS stealer targets crypto enthusiasts and developers" on SecureList, detailing the six-stage infection chain, encryption keys, C2 API, and backdoor commands.
  • BleepingComputer reports on MacSync's use of public iCloud calendars to deliver new payloads.
  • Help Net Security publishes coverage summarizing the Kaspersky findings on MacSync's fake Toria wallet lure and iCloud calendar abuse.
  • Additional security media outlets (CyberSecurityNews, TechNadu, Cyberpress, PRSOL:CC) publish further analysis of the infection chain and developer/crypto-user targeting.

Sources cited for MacSync (Mac.c) macOS Info-Stealer Abuses Public iCloud

More in malware

Detection coverage for TL-2026-2723

As of 2026-09-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2723 across Splunk SPL, Microsoft KQL and Sigma, covering 26 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats