Home · Technology · Oct 4 archive

MacSync Malware Hides Commands in iCloud Calendar

Confirmed

Technology Desk

In Short: While MacSync malware uses iCloud calendars to hide commands, it is important for users to remain vigilant and secure their devices by regularly updating software and being cautious with downloads.

Researchers have discovered a new tactic used by the MacSync malware, an information-stealing malware family targeting macOS devices. The malware hides commands within public iCloud calendar events to download additional malicious software.

According to Fox News, the calendar itself does not infect your computer simply by receiving an invitation. However, once MacSync gains access, it can steal a wide range of data beyond just calendar entries.

Microsoft Threat Intelligence tracked a shift in the macOS ClickFix operation, which now uses Terminal commands to fetch remote scripts instead of shipping disk images. This shift includes server-side gates that hide malicious pages from crawlers and sandboxes.

The server-side gate presents selected Mac users with a fake software download, while probes specifically hunt for analysts by checking if the browser's developer console is open or if the browser is faking codec support in JavaScript.

Google's new product, CC, allows family members to share calendars and task lists, pooling information from Gmail, Calendar, and Drive. This feature helps manage household schedules and reminders more efficiently.

Caddy, an AI assistant featured in TechCrunch, turns scattered information on phones into actionable tasks, such as scheduling appointments, organizing calendars, or sending emails.

What this adds

The iCloud calendar trick highlights the evolving tactics of malware creators who exploit trusted services to hide malicious activities.

What's confirmed

What's still developing

Sources