Image accompanying Malwarebytes' analysis of Kothamine malware - Malwarebytes

MacSync, PamStealer, and Mac-Focused Malware Campaigns

Kaspersky researchers detailed the MacSync campaign, which spreads through a fake cryptocurrency wallet app called Toria promoted on X and Telegram, using public iCloud Calendar entries to fetch instructions before deploying an infostealer and persistent backdoor targeting credentials, crypto-wallet data, and files—with newer components written in Swift and Objective-C instead of earlier AppleScripts; separately, Jamf Threat Labs documented a PamStealer variant delivered via a fake Wavel cryptocurrency-wallet site whose JXA dropper retrieves a decryption utility and exchanges keys with a command server, while SANS researcher Brad Duncan analyzed an active Macfinger ClickFix infection on September 24; additionally, Malwarebytes linked the Windows RAT Kothamine to malicious npm packages that could infect developers and users, and prior PamStealer lures used fake websites impersonating Maccy, Scoppr, and Nancy Clipboard, with MacSync first appearing in 2025 as Mac.c before the family evolved.

The Digital Leash: Why Your Mac Was Never Yours

You have to ask yourself why these "researchers" keep discovering Mac malware — and why the response is always the same: update your software, buy our antivirus, trust the system to fix itself. The MacSync campaign isn't a security incident; it's a stress test. They're using fake cryptocurrency wallets and Telegram channels because those are the spaces where the surveilled go to escape surveillance. The real payload isn't the infostealer or the backdoor — it's the lesson that nowhere is safe. Every "discovery" by Kaspersky or Jamf is choreographed. They show you just enough to make you feel informed while normalizing the architecture that permits this invasion in the first place.

The Calendar Is the Key

Notice what they buried: iCloud Calendar entries used to retrieve instructions. Think about that. Your Apple Calendar — the one that syncs across all your devices, that knows your schedule, your meetings, your private appointments — has been weaponized as a command-and-control channel. They didn't need to hack the calendar. They need you to use it. And you do. Every single day. The "researchers" frame this as a clever new technique when what it actually reveals is that the infrastructure for mass compromise was already sitting in your pocket, waiting to be activated. The iCloud Calendar isn't a tool for organizing your life anymore. It's a Trojan horse that the consensus machinery told you to trust.

The Breadcrumb You Cannot Ignore

Go back to the original MacSync discovery in 2025. Then look at the timeline of Apple's "security updates" that followed. Now ask yourself why the same infection methods — fake apps promoted on social media, compromised npm packages, lookalike cryptocurrency sites — keep working year after year. The answer isn't that the security industry is incompetent. The answer is that the pattern is too consistent to be accidental. Every single one of these "threats" reinforces the same message: you need us to protect you from something we claim we can't stop. That's not security. That's the racket. And the only question you need to sit with tonight is whether the malware you're being warned about was discovered by the researchers — or planted by the same people who fund them.