Plan
active
MacSync malware uses iCloud calendar events as C2 channel
- Engineer — Learn: Novel technique of abusing legitimate iCloud calendar infrastructure as a command-and-control channel; no KEV, PoC, or active exploitation signals, but worth understanding for macOS fleet defenders designing egress controls around trusted Apple services.
- SOC/IR — Plan: Build or tune detections for macOS processes making anomalous iCloud Calendar API calls (calendar.google.com analogue: p-calendarws.icloud.com) or reading public calendar events at unusual intervals — this C2 pattern will evade domain blocklists targeting known C2 infrastructure.
- Leader — Skip
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.