Kaspersky says a new MacSync variant hides its payload commands in public iCloud calendar events and downloads the next stage from iCloud. Both the instructions and the download ride trusted Apple domains, past defenses that block known-bad hosts.
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence68
Kaspersky says the macOS stealer it first tracked as Mac.c has swapped script droppers for FAT Mach-O binaries in a chain found in September 2026, and its loader now reads shell commands out of a public iCloud calendar file.
Reality
- Evidence68
- Adoption32
- Hype gap0
- Incentives58
- Confidence58
Unit 42 followed the copy-paste instructions on Aug. 5, 2026, and watched one Zsh command install AMOS twice over and package a lab Mac's wallet folders and cloud credentials into a single zip.
Reality
- Evidence70
- Adoption30
- Hype gap−10
- Incentives40
- Confidence62
Huntress tracked nine months of malware campaigns run through shipped AI sharing features. Public Claude Artifacts, claude.ai/share links and indexable ChatGPT and Grok conversations all put the lure on a domain the victim already trusts.
Reality
- Evidence45
- Adoption38
- Hype gap+12
- Incentives85
- Confidence50
Huntress says a researcher targeted after Black Hat and Def Con was sent a Google Doc that rendered an Apps Script sidebar with ClickFix instructions. The lure arrived by DM, not email.
Reality
- Evidence68
- Adoption34
- Hype gap+14
- Incentives62
- Confidence66