A new MacSync information-stealer variant targeting macOS uses public iCloud calendar events to deliver fresh payloads, BleepingComputer reports. The technique illustrates how attackers can repurpose legitimate cloud services as a content-delivery channel, complicating blocklists that rely only on domain reputation.

Organizations with macOS fleets should review endpoint telemetry for suspicious calendar-linked activity, unexpected downloads, and persistence mechanisms. Users should be reminded that a calendar invite or event can still be part of a social-engineering chain; a familiar cloud brand does not validate the content linked from it.

Defensive measures include keeping macOS and security tooling current, limiting execution of untrusted code, monitoring outbound connections and credential access, and triaging alerts that involve unusual Calendar or browser activity. Security teams should avoid broad service blocks without evaluating business impact, but can use the reported indicators and behaviors to inform detection and hunting.

Source: BleepingComputer.

By Allan