New MacSync Stealer Malware Attacking macOS Users Using Digitally Signed Apps
ID: 846ea8be-0350-5206-be2c-73220ed4a6b8
STIX ID: report--846ea8be-0350-5206-be2c-73220ed4a6b8
Feed Name: cybersecurityNews.com
A new MacSync Stealer variant targets macOS users via a digitally signed and notarized fake installer (zk-call-messenger-installer-3.9.2-lts.dmg, signed with Apple Developer Team ID GNJLS3UYZ4). The Swift-based runtimectl helper checks connectivity, downloads a second-stage shell script from gatemaden.space, removes quarantine flags, sets execution permissions, rate-limits itself, deletes traces, and communicates with focusgroovy.com for additional payloads and C2, enabling silent data theft; Jamf reported the actor and Apple revoked the certificate.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
