macOS Trojan Upgrades: Spreading through Signed App, Encrypting Users Face More Covert Risk
BlockBeats News, December 23, SlowMist Chief Security Officer 23pds shared a post stating that the MacSync Stealer malware active on the macOS platform has undergone significant evolution, with user assets already being stolen. The article shared by him mentioned that from earlier reliance on "drag-and-drop to Terminal" and "ClickFix" and other low-threshold inducement methods, it has upgraded to code signing and through Apple notarized Swift applications, significantly improving its stealthiness.
Researchers found that this sample is being spread in the form of a disk image named zk-call-messenger-installer-3.9.2-lts.dmg, disguised as instant messaging or utility applications to induce users to download. Unlike before, the new version no longer requires any terminal operation by the user but is pulled and executed by a built-in Swift helper from a remote server to complete the information theft process.
This malware has been code signed and notarized by Apple, with the developer team ID being GNJLS3UYZ4, and the related hash has not been revoked by Apple during analysis. This means that it has a higher "trust level" under macOS's default security mechanisms, making it easier to bypass user vigilance. Research also found that the DMG file is unusually large, containing decoy files related to LibreOffice PDFs, among others, to further reduce suspicion.
Security researchers pointed out that such information-stealing trojans often target browser data, account credentials, and cryptocurrency wallet information. As malware begins to systematically abuse Apple's signing and notarization mechanism, cryptocurrency users in the macOS environment are facing an increasing risk of phishing and private key leaks.
Users are strongly advised to ensure that threat prevention and advanced threat control are enabled in Jamf for Mac and set to blocking mode to defend against these latest variants of information-stealing malware.
You may also like

Kalshi early employees: Whoever controls the traffic controls the market

Tether signs contracts with four major audits, Circle's compliance moat collapses, stock price plummets by 20%

Proudly Introducing Aethir Claw: Your AI Agent, Our Infrastructure

Why Buying Gold Can Lead to Bankruptcy

If the US Treasury yield rises above 5%, will Bitcoin drop below $50,000?

Circle Plunges 20%: Crypto Earthquake Triggered by Draft Proposal

After the Smoke Clears: 5 Possible Endings to the Middle East Conflict

Stablecoin Yields Discontinued, Circle Plunges 20% in One Day

AI Wired into War Machine | Rewire News Nightly

Web3 is sick, but the cure is not AI

Why must Web3 projects be included in RootData?

Fluid Announces Updates on Resolv Hack Recovery and Compensation Plan
Key Takeaways Fluid has repaid approximately $70 million related to USR debts on the BNB and Plasma chains.…

Binance to Delist Key Spot Trading Pairs: What You Need to Know
Key Takeaways Binance is set to remove several spot trading pairs on March 27, 2026, at 11:00 AM…

Whale Activities in the Crypto Market: A Deep Dive into Recent Trends
Key Takeaways A significant whale deposit occurred 3 hours ago when 5.5 million USDT was moved to Binance…

Circle and Tether Freeze Iranian Exchange Wallex Wallet with $2.49M Assets on Hold
Key Takeaways Circle and Tether have frozen a significant amount of assets from an Iranian exchange called Wallex,…

James Wynn Engages in High-Leverage Bitcoin Short Position
Key Takeaways James Wynn recently opened a 40x leveraged short position on Bitcoin. His position involves 2.69 BTC,…

Major Whale Opens Significant 20x Leveraged Positions in ETH and BTC
Key Takeaways Whale 0x049b has executed large 20x leverage positions on 9,256 ETH and 282.47 BTC, totaling over…

New Whale Activity: 33,998 ETH Withdrawn from Kraken
Key Takeaways A new Ethereum whale with the address starting 0xD77 has withdrawn 33,998 ETH from Kraken. The…
