Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

macOS Flaw Lets Standard Users Disable EDR and MDM

June 26, 2026

Crypto Clipper Campaign Abuses Fake Reviews, AI Narrators, and VirusTotal Comments

June 26, 2026

Major Increase in Ransomware Attacks Targeting Europe, Warns Report

June 26, 2026
Facebook X (Twitter) Instagram
Friday, June 26
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Reworked MacSync Stealer Adopts Quieter Installation Process
News

Reworked MacSync Stealer Adopts Quieter Installation Process

Team-CWDBy Team-CWDDecember 23, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A newly identified macOS malware sample that disguises itself as a legitimate, signed application has been uncovered during routine threat monitoring.

The malware, a reworked version of the MacSync Stealer, departs from earlier delivery methods and adopts a quieter, more automated installation process.

The sample was detected by Jamf Threat Labs while reviewing alerts triggered by internal YARA rules. 

Technical Observations From Analysis

Unlike previous MacSync Stealer variants that relied on user interaction via ClickFix or Terminal-based tricks, this version arrives as a Swift application that is both code-signed and notarized by Apple. It is distributed inside a disk image posing as a messaging app installer and requires no command-line involvement.

Once launched, the application silently retrieves an encoded script from a remote server and executes it through a helper component. Jamf noted that similar techniques have recently appeared in other macOS infostealers, including newer versions of Odyssey.

Despite being signed, the installer still displayed instructions prompting users to right-click and select Open, a tactic commonly used to bypass Gatekeeper warnings.

Inspection confirmed the application was built as a universal Mach-O binary and signed under a developer certificate that, at the time of discovery, had not been revoked.

The disk image stood out for its unusually large size of 25.5MB, inflated with decoy files such as unrelated PDF documents.

Detection rates varied. Some samples uploaded to VirusTotal were flagged by only one security engine, while others were identified by up to thirteen. Most detections classified the files as generic downloaders.

Read more on macOS malware distribution: New FlexibleFerret Malware Chain Targets macOS With Go Backdoor

Jamf later reported the associated developer certificate to Apple, which has since revoked it.

How the Dropper Operates

The Swift-based dropper performs several checks before executing its payload, including:

  • Verifying internet connectivity before proceeding

  • Enforcing a minimum execution interval of around 3600 seconds

  • Downloading the payload using a modified curl command designed to avoid detection

  • Removing quarantine attributes and validating the file before execution

The malware runs largely in memory and cleans up temporary files after execution, leaving minimal traces behind. Its behavior mirrors previous MacSync Stealer campaigns once the second-stage payload is deployed.

“While MacSync Stealer itself is not entirely new, this case highlights how its authors continue to evolve their delivery methods,” Jamf Threat Labs said.

“This shift in distribution reflects a broader trend across the macOS malware landscape, where attackers increasingly attempt to sneak their malware into executables that are signed and notarized, allowing them to look more like legitimate applications. By leveraging these techniques, adversaries reduce the chances of being detected early on.”

Image credit: Nanain / Shutterstock.com



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleApple 0-Days, WinRAR Exploit, LastPass Fines, .NET RCE, OAuth Scams & More
Next Article FreePBX Patches Critical SQLi, File-Upload, and AUTHTYPE Bypass Flaws Enabling RCE
Team-CWD
  • Website

Related Posts

News

macOS Flaw Lets Standard Users Disable EDR and MDM

June 26, 2026
News

Crypto Clipper Campaign Abuses Fake Reviews, AI Narrators, and VirusTotal Comments

June 26, 2026
News

New CISA Guide Helps Agencies Adopt SASE For Zero Trust

June 25, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Common Apple Pay scams, and how to stay safe

January 22, 2026

When ‘hacking’ your game becomes a security risk

October 17, 2025

What it is and how to protect yourself

January 8, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.