logo

From ClickFix to code signed: the quiet shift of MacSync Stealer malware

ID: aaed1855-f19e-53e9-8de5-eaa8197e0b3a

STIX ID: report--aaed1855-f19e-53e9-8de5-eaa8197e0b3a

Feed Name: Jamf Blog

Threat Score
72/100

Date Published: 2025-12-17

Date Updated: 2026-07-16

...
...

MacSync Stealer has evolved from user-interaction tricks to a stealthier distribution: a code-signed, notarized Swift dropper packaged in DMGs that fetches and executes an obfuscated shell payload, performs Gatekeeper/quarantine removal, enforces rate-limiting and network checks, and ultimately installs an infostealer; the Jamf Threat Labs report includes detailed behavior, IoCs (hashes, domain, URL, TeamID), and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.