MacSync variant hides commands in iCloud Calendar to steal Mac users’ data
Kaspersky researchers say a new MacSync variant combines an infostealer with a persistent backdoor targeting credentials, cryptocurrency wallet data and files. The malware was distributed through a crypto-wallet app called Toria, promoted on X and Telegram, and reportedly uses an iCloud calendar to conceal malicious commands.
Why it matters Mac users installing Toria risk exposing ordinary files and credentials, not just crypto assets. The reported persistent backdoor also makes the threat more than a one-time data theft.
HelpNet Security ↗