From ClickFix to code signed: the quiet shift of MacSync Stealer malware
ID: aaed1855-f19e-53e9-8de5-eaa8197e0b3a
STIX ID: report--aaed1855-f19e-53e9-8de5-eaa8197e0b3a
Feed Name: Jamf Blog
Threat Score
MacSync Stealer has evolved from user-interaction tricks to a stealthier distribution: a code-signed, notarized Swift dropper packaged in DMGs that fetches and executes an obfuscated shell payload, performs Gatekeeper/quarantine removal, enforces rate-limiting and network checks, and ultimately installs an infostealer; the Jamf Threat Labs report includes detailed behavior, IoCs (hashes, domain, URL, TeamID), and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
