MacSync (Mac.c) macOS Info-Stealer Abuses Public iCloud Calendars as C2 Dead-Drop in Fake "Toria" Crypto Wallet Campaign
MacSync (Mac.c) macOS Info-Stealer Abuses Public iCloud (TL-2026-2723), also tracked as Mac.c, is a high-severity malware campaign, first published 2026-09-27. It has no confirmed attribution, affects Apple macOS, maps to 17 MITRE ATT&CK techniques (T1005, T1027, T1036.005), and is covered by 9 detection rules and 26 indicators of compromise.
Key facts for TL-2026-2723
- Threat ID
- TL-2026-2723
- Also known as
- Mac.c
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-09-27
- Last reviewed
- 2026-09-27
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- technology, cryptocurrency
- Detection rules
- 9
- Indicators of compromise
- 26
Malware and tooling in MacSync (Mac.c) macOS Info-Stealer Abuses Public iCloud
Malware and tooling: MacSync, Toria, http://caldav.icloud.com/published/2/MTk1NDMwMDMzNTUxOTU0M1aHCZ-nMxiyGzBTzPiodOf44DtKJ6PpjftAG28_ui2NCYMpL_vu4pF4ddsJ8ysg0QI7pR0VEIEbZYdilVZRw08
Kaspersky (researcher Sergey Puzan) identified a new version of the MacSync (aka Mac.c) macOS infostealer distributed via a fake cryptocurrency wallet app named Toria, promoted on X and Telegram. The malware's six-stage infection chain hides a downloader link inside a public iCloud calendar event and ultimately deploys a Swift/Objective-C infostealer and a Finder-disguised backdoor that harvest browser, crypto-wallet, Keychain, SSH/AWS/Kubernetes/Git, and Telegram data.
How MacSync (Mac.c) macOS Info-Stealer Abuses Public iCloud works
MacSync, first observed in 2025 under the name Mac.c as an AppleScript-based stealer resembling the AMOS (Atomic macOS Stealer) family, resurfaced in September 2026 with a substantially reworked, compiled Swift/Objective-C payload and a novel command-delivery mechanism. The current campaign lures victims -- primarily macOS developers, IT-associated users, and cryptocurrency holders -- with a fake wallet application called "Toria," advertised via a dedicated website (toria.app) and promoted through X and Telegram accounts.
The infection begins with a malicious DMG containing a compiled JXA loader that strips the macOS quarantine attribute (xattr -cr) and decodes an XOR-encrypted (key 73 6f 6e 6f 6d 61 62 6c 64 07) downloader URL. That URL points to a public iCloud CalDAV calendar (caldav.icloud[.]com/published/2/...); the loader fetches the calendar's raw text and pipes it to zsh. Most of the calendar body is inert text that produces shell errors, but the malware places live commands immediately after the event's DESCRIPTION: field, which zsh executes -- a dead-drop technique that abuses a legitimate Apple sharing feature and leaves no attacker-controlled infrastructure in the initial fetch. Those commands retrieve an AES-CBC-encrypted TAR.GZ (first dropper), which in turn unpacks a second dropper that performs VM detection (sysctl kern.hv_vmm_present, machdep.cpu.brand_string) and sets PT_DENY_ATTACH to block debuggers before decrypting and executing a fifth-stage script. That script downloads the final infostealer and backdoor modules using a custom pkgunpack utility implementing Curve25519 ECDH key exchange and AES-GCM decryption.
The backdoor persists via a LaunchAgent labeled com.apple.finder.agent (masquerading as Finder), a .zshrc modification that runs a hidden .repair-run recovery script, and global git pre-commit/post-checkout hooks. The .repair-run script restores backdoor files from a backup at $HOME/Library/Application Support/System if they are removed, and kills BTMNotificationAgent, NotificationCenter, and BackgroundTaskManagementAgent to suppress macOS's background-task notifications. The backdoor exposes AppleScript-wrapped commands including deploy_ext (malicious browser extension installation), deploy_ledger (Ledger hardware-wallet software replacement), regrab (re-collects host data into /tmp/osalogging.zip), and live_browser (an adversary-in-the-middle traffic interceptor via an sn_relay component).
The infostealer module harvests browser history, cookies, saved credentials and Safe Storage keys (Chrome, Brave), cryptocurrency wallet extension/app data, Telegram files, the Keychain file, SSH/zsh/AWS/Kubernetes/Git configuration files, shell command history, and system/process/application inventory. Collected data is uploaded to the C2 over authenticated PUT requests (custom X-Upload-Token header) in 90-megabyte chunks via a documented REST API (GET /v1/agent/ping, POST /v1/agent/refresh, POST /v1/asset/<id>/init, PUT /v1/asset/<id>). C2 and staging infrastructure impersonates well-known brands (Apple App Store, Slack, StreamYard) under domains such as toria.apple03cloudstore[.]com, docsend.appstore[.]com[.]mx, streamyard.appstore[.]com[.]mx, slack.apple03cloudstore[.]com, and waaako.appstore[.]com[.]mx.
MITRE ATT&CK techniques used in TL-2026-2723
Collection
T1005 Data from Local System; T1074.001 Data Staged: Local Data Staging; T1557 Adversary-in-the-Middle
Defense Evasion
T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1497.001 Virtualization/Sandbox Evasion: System Checks; T1622 Debugger Evasion
Persistence
T1176 Software Extensions; T1543.001 Create or Modify System Process: Launch Agent; T1546.004 Event Triggered Execution: Unix Shell Configuration Modification
Execution
T1204.002 User Execution: Malicious File
Credential Access
T1539 Steal Web Session Cookie; T1552.001 Unsecured Credentials: Credentials In Files; T1555.001 Credentials from Password Stores: Keychain
defense-impairment
T1553.001 Subvert Trust Controls: Gatekeeper Bypass; T1685 Disable or Modify Tools
Resource Development
Affected products and versions in MacSync (Mac.c) macOS Info-Stealer Abuses Public iCloud
- Apple — macOS
Vulnerable versions: All supported macOS versions (delivered via trojanized application and social engineering, not a software vulnerability)
Remediation for MacSync (Mac.c) macOS Info-Stealer Abuses Public iCloud
Patches
- No vendor patch applies; MacSync is delivered via social engineering and a trojanized application, not a software vulnerability.
Immediate actions
- Block the identified C2 and staging domains/URLs (toria.app, toria.apple03cloudstore.com, docsend.appstore.com.mx, streamyard.appstore.com.mx, slack.apple03cloudstore.com, waaako.appstore.com.mx, warpcast.asia) at DNS/proxy/firewall.
- Hunt for and remove the com.apple.finder.agent LaunchAgent, .zshrc modifications referencing a .repair-run script, and global git pre-commit/post-checkout hooks on macOS endpoints.
- On any confirmed-infected host, rotate SSH keys, AWS credentials, Kubernetes kubeconfigs, Git credentials/tokens, browser-saved passwords, and Keychain-protected secrets, and revoke active browser session cookies.
- Inspect and remove any unauthorized browser extensions and check for Ledger/hardware-wallet software tampering on affected hosts.
Workarounds
- Do not download or run cryptocurrency wallet applications advertised via X/Telegram links; verify publisher identity and obtain wallet software only from official vendor sites or the Mac App Store.
- Restrict or monitor use of public/shared iCloud calendar subscriptions on managed macOS fleets.
Longer-term hardening
- Deploy EDR/behavioral monitoring on macOS fleets for zsh processes spawned from curl/network fetches to iCloud/CalDAV endpoints, xattr -cr invocations, and PT_DENY_ATTACH/anti-VM syscall patterns.
- Monitor outbound HTTP PUT requests with custom auth headers (e.g., X-Upload-Token) and large (~90MB) chunked uploads to unrecognized domains.
- Enforce application allow-listing / Gatekeeper notarization checks and alert on DMG installations that strip quarantine attributes shortly after download.
- Educate developer and crypto-holding staff on the risk of installing wallet/crypto apps from social-media-promoted links rather than official app stores or vendor sites.
Timeline of MacSync (Mac.c) macOS Info-Stealer Abuses Public iCloud
- MacSync first emerges under the name Mac.c as an AppleScript-based macOS infostealer resembling the AMOS (Atomic macOS Stealer) family.
- Kaspersky researcher Sergey Puzan identifies a reworked MacSync variant using a public iCloud calendar as a C2 dead-drop and compiled Swift/Objective-C infostealer and backdoor payloads.
- Kaspersky publishes the technical analysis "A new version of the MacSync macOS stealer targets crypto enthusiasts and developers" on SecureList, detailing the six-stage infection chain, encryption keys, C2 API, and backdoor commands.
- BleepingComputer reports on MacSync's use of public iCloud calendars to deliver new payloads.
- Help Net Security publishes coverage summarizing the Kaspersky findings on MacSync's fake Toria wallet lure and iCloud calendar abuse.
- Additional security media outlets (CyberSecurityNews, TechNadu, Cyberpress, PRSOL:CC) publish further analysis of the infection chain and developer/crypto-user targeting.
Sources cited for MacSync (Mac.c) macOS Info-Stealer Abuses Public iCloud
- MacSync info-stealing malware for macOS
- A new version of the MacSync macOS stealer targets crypto enthusiasts and developers
- MacSync malware uses public iCloud calendars to deliver new payloads
- New MacSync Malware Turns macOS Apps Into Tools for Crypto and Password Theft
- MacSync macOS Infostealer Adds Binary Payloads, iCloud Abuse
- MacSync's New Infection Chain Shows How Mac Malware Is Becoming More Sophisticated
- MacSync malware uses public iCloud calendars to deliver new payloads
More in malware
- TWEAKOS Stealer: Discord Token Theft and Telegram Account-Takeover Marketplace
- Infostealer Market Resilience: Law Enforcement Takedowns Displace, Not Eliminate, RedLine/META/LummaC2/Rhadamanthys Activity
- ClickFix Campaign Abuses Compromised Ukrainian Websites to Deploy Psychedelic Stealer
- CARBONATO Botnet Exploits Exposed Docker Daemons to Deploy AI Agent Framework, Prioritizes AI API Key Theft
- The Infostealer Incursion: Stolen Credentials Breach Cloud, Code, and AI Environments
Detection coverage for TL-2026-2723
As of 2026-09-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2723 across Splunk SPL, Microsoft KQL and Sigma, covering 26 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.