Tuesday, May 6, 2025
HomemacOSHackers Install macOS Malware Using Weaponised Calendar Invites

Hackers Install macOS Malware Using Weaponised Calendar Invites

Published on

SIEM as a Service

Follow Us on Google News

Hackers use weaponized calendar invites to exploit vulnerabilities in email systems, tricking users into clicking on malicious links or downloading malware disguised as event attachments. 

By leveraging trust in calendar invitations, threat actors increase the likelihood of successful phishing attacks and unauthorized access to sensitive information.

Cybersecurity researchers at Malwarebytes recently discovered that hackers are actively exploiting the weaponized calendar invites to install macOS malware.

- Advertisement - Google News

macOS Malware Calendar Invites

Mac users seeking cryptocurrency opportunities are targeted by cybercriminals using fake calendar invites.

Document
Integrate ANY.RUN in your company for Effective Malware Analysis

Are you from SOC and DFIR teams? – Join With 400,000 independent Researchers

Malware analysis can be fast and simple. Just let us show you the way to:

  • Interact with malware safely
  • Set up virtual machine in Linux and all Windows OS versions
  • Work in a team
  • Get detailed reports with maximum data
  • If you want to test all these features now with completely free access to the sandbox: ..


Links sent during attacks install malware on the target’s machine. 

Brian Krebs flagged the issue, and asserted that scammers pose as cryptocurrency investors, and lure people into fake partnership meetings on Telegram.

Luring message (Source – MalwareBytes)

Signum Capital issued a warning about impersonation attempts on Twitter in January.

Threat actors contact the targets via Telegram DMs in which they lure their targets by offering opportunities for calls or meetings.

Interested targets receive fake meeting invitations. 

When victims attempt to join, the link fails. Scammers blame regional access restrictions and advise running a script to fix it. 

Malwarebytes’ Thomas Reed confirmed threat actors’ use of scripts to compromise users isn’t new.

AppleScripts come in .scpt files, but victims need to open in Script Editor and may spot the code.

AppleScript applets act like normal apps, enhancing trustworthiness with code signing and icons. 

Script Editor (Source – MalwareBytes)

Due to this obfuscating the code is possible which makes it less likely for Apple’s notarization process to detect potential threats.

When a user enters their password, the script doesn’t see it but gains root access. Actions run with administrator privileges without additional authentication. 

The script can easily trick users into granting root permissions through a standard authentication request dialog.

AppleScript excels at malware crafting. Certain malicious programs like OSX.DubRobber, OSX.OSAMiner utilized AppleScript solely or near-solely.

A basic Apple Script, in this case, downloaded and ran a macOS Trojan whose purpose is unknown.

If it’s revealed as a cryptocurrency-stealing banking Trojan, then it wouldn’t be surprising.

How To Recognize The Scam?

Here below we have mentioned all the key tactics used by the threat actors, and these tactics will help in recognizing the scam:-

  • DM approach on Telegram
  • Crypto investment lure
  • Calendly platform preferred
  • Fake “regional restriction” urgency
  • Script with .scpt extension
  • Hosted on a fake meeting support site

You can block malware, including Trojans, ransomware, spyware, rootkits, worms, and zero-day exploits, with Perimeter81 malware protection. All are incredibly harmful, can wreak havoc, and damage your network.

Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter

Tushar Subhra
Tushar Subhra
Tushar is a Cyber security content editor with a passion for creating captivating and informative content. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news.

Latest articles

BFDOOR Malware Targets Organizations to Establish Long-Term Persistence

The BPFDoor malware has emerged as a significant threat targeting domestic and international organizations,...

Uncovering the Security Risks of Data Exposure in AI-Powered Tools like Snowflake’s CORTEX

As artificial intelligence continues to reshape the technological landscape, tools like Snowflake’s CORTEX Search...

UNC3944 Hackers Shift from SIM Swapping to Ransomware and Data Extortion

UNC3944, a financially-motivated threat actor also linked to the group known as Scattered Spider,...

Over 2,800 Hacked Websites Targeting MacOS Users with AMOS Stealer Malware

Cybersecurity researcher has uncovered a massive malware campaign targeting MacOS users through approximately 2,800...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

BFDOOR Malware Targets Organizations to Establish Long-Term Persistence

The BPFDoor malware has emerged as a significant threat targeting domestic and international organizations,...

Over 2,800 Hacked Websites Targeting MacOS Users with AMOS Stealer Malware

Cybersecurity researcher has uncovered a massive malware campaign targeting MacOS users through approximately 2,800...

Popular Instagram Blogger’s Account Hacked to Phish Users and Steal Banking Credentials

A high-profile Russian Instagram blogger recently fell victim to a sophisticated cyberattack, where scammers...