Indicators of compromise · MacSync — 4 shown
yoauction[.]comzanderrealestate[.]comhxxps://zanderrealestate[.]com/curl/85cb26206d920216eee0c5f67e8de516b4d55bd1752025bb3c08a069a44fdbdffbc460f7b29d7e709c28fc9368a592f3140fdb51fff5de54471450e250b6345a
Defanged third-party indicators (abuse.ch). The defanging is deliberate: never click, resolve or fetch these values. An indicator corroborates a report — it never proves one, and its presence here does not mean this story's hosts are listed.
Kaspersky has documented a new MacSync delivery chain in which a downloader fetches commands hidden in the DESCRIPTION field of a public iCloud calendar event, feeds the retrieved text to macOS's zsh shell, and relies on the fact that most of the calendar text produces errors while the commands after the description line run and fetch an archive containing the malware components. The archive's APP bundle acts as a dropper for further stages. The infostealer module is largely unchanged, targeting browser history, cookies and saved credentials, crypto wallet extensions and application data, Telegram data, the Keychain file, system and device information, and SSH, AWS, Kubernetes, Git and shell configuration files. What is new is an Objective-C backdoor that disguises itself as Finder and establishes persistence through a LaunchAgent, .zshrc modifications and global Git hooks while terminating macOS notification processes so alerts do not reach the user; it can run attacker-supplied AppleScript from its command server, deploy a browser extension or replace an installed Ledger wallet app, and collect and upload files. The campaign was also delivered as a fake crypto wallet site called Toria.
| Attribute | Detail |
|---|---|
| Sector | Global (Macro) |
| Date | 2026-09-26 |
| Source | BleepingComputer |
| Reliability | Tier 2 |