security1 publisher
MacSync now pipes a public iCloud calendar into zsh to stage its Mac payload
Kaspersky says the macOS stealer it first tracked as Mac.c has swapped script droppers for FAT Mach-O binaries in a chain found in September 2026, and its loader now reads shell commands out of a public iCloud calendar file.
Publishers:securelist.com
Reality
- Evidence68
- Adoption32
- Hype gap0
- Incentives58
- Confidence58