CuraSec

Plan active

MacSync malware uses iCloud calendar events as C2 channel

2026-09-25 15:49 UTC · BleepingComputer · read the source ↗ #macos#malware#c2
  • Engineer — Learn: Novel technique of abusing legitimate iCloud calendar infrastructure as a command-and-control channel; no KEV, PoC, or active exploitation signals, but worth understanding for macOS fleet defenders designing egress controls around trusted Apple services.
  • SOC/IR — Plan: Build or tune detections for macOS processes making anomalous iCloud Calendar API calls (calendar.google.com analogue: p-calendarws.icloud.com) or reading public calendar events at unusual intervals — this C2 pattern will evade domain blocklists targeting known C2 infrastructure.
  • Leader — Skip
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.