In a technical analysis published Sept. 24, 2026, Kaspersky said it had first spotted the substantially changed MacSync chain in the wild that September. At least one analyzed sample used a public iCloud Calendar file as a later delivery step—but only after malicious software had reached and run on the Mac.

How the calendar file led to another download

Kaspersky found a MacSync sample using a public iCloud Calendar file

For this reported chain, the calendar was not the starting point: malicious software had already reached and run on the Mac. Kaspersky says the downloader’s next-stage URL pointed to a public iCloud Calendar file in .ics format, then passed its contents line by line to Zsh, a shell interpreter.

Ordinary calendar lines produced invalid-command errors. Malicious instructions after the DESCRIPTION: line led to another download: a compressed archive from iCloud containing an application that began another stage of the infection. Other analyzed samples pointed to attacker-controlled servers instead of a public calendar file.

What MacSync targeted and how its backdoor persisted

Kaspersky describes MacSync as an infostealer distributed as malware-as-a-service, alongside a separate backdoor. The infostealer can target browser history, cookies and saved credentials; cryptocurrency-wallet and Telegram data; the device password and Keychain; and system and developer information. The latter includes installed-app and process details, SSH, ZSH, AWS, Kubernetes and Git configurations, plus Zsh and Bash command histories.

The backdoor disguises itself as Finder. Kaspersky reports that it can persist through a LaunchAgent, changes to .ZSHRC and global Git hooks. Kaspersky also associates its commands with deploying a browser extension, replacing an installed Ledger wallet app, and collecting system information and files.

What Kaspersky says about live_browser and sn_relay

The live_browser command downloads a component named sn_relay; Kaspersky says its exact purpose is undetermined.

Kaspersky’s practical precautions

Kaspersky recommends checking that software comes from its original developer and treating an administrator-password request from an unfamiliar app with caution.