New MacSync Stealer Uses Signed macOS App to Evade Gatekeeper and Steal Data
ID: 41d2301a-221e-5362-900a-43e61775581a
STIX ID: report--41d2301a-221e-5362-900a-43e61775581a
Feed Name: cybersecurityNews.com
Jamf Threat Labs and reporting describe a new notarized, code-signed MacSync macOS stealer that masquerades as legitimate apps (notably targeting users of messaging apps like zk-Call) to bypass Gatekeeper; this variant uses a large 25.5MB disk image, can install backdoors, steal browser data and cryptocurrency wallet credentials, and fetch additional payloads from the identified C2 domain focusgroovy.com, with possible distribution via malvertising, social media, search-engine manipulation, or spear-phishing — users are urged to avoid installing untrusted signed apps.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
