In a technical analysis published Sept. 24, 2026, Kaspersky said it had first spotted the substantially changed MacSync chain in the wild that September. At least one analyzed sample used a public iCloud Calendar file as a later delivery step—but only after malicious software had reached and run on the Mac.
How the calendar file led to another download
For this reported chain, the calendar was not the starting point: malicious software had already reached and run on the Mac. Kaspersky says the downloader’s next-stage URL pointed to a public iCloud Calendar file in .ics format, then passed its contents line by line to Zsh, a shell interpreter.
Ordinary calendar lines produced invalid-command errors. Malicious instructions after the DESCRIPTION: line led to another download: a compressed archive from iCloud containing an application that began another stage of the infection. Other analyzed samples pointed to attacker-controlled servers instead of a public calendar file.
What MacSync targeted and how its backdoor persisted
Kaspersky describes MacSync as an infostealer distributed as malware-as-a-service, alongside a separate backdoor. The infostealer can target browser history, cookies and saved credentials; cryptocurrency-wallet and Telegram data; the device password and Keychain; and system and developer information. The latter includes installed-app and process details, SSH, ZSH, AWS, Kubernetes and Git configurations, plus Zsh and Bash command histories.
The backdoor disguises itself as Finder. Kaspersky reports that it can persist through a LaunchAgent, changes to .ZSHRC and global Git hooks. Kaspersky also associates its commands with deploying a browser extension, replacing an installed Ledger wallet app, and collecting system information and files.
What Kaspersky says about live_browser and sn_relay
The live_browser command downloads a component named sn_relay; Kaspersky says its exact purpose is undetermined.
Kaspersky’s practical precautions
Kaspersky recommends checking that software comes from its original developer and treating an administrator-password request from an unfamiliar app with caution.