logo

New MacSync Stealer Disguised as Trusted Mac App Hunts Saved Passwords

ID: 3c29ca5a-a0c1-5227-a30d-6d4bfdc28d58

STIX ID: report--3c29ca5a-a0c1-5227-a30d-6d4bfdc28d58

Feed Name: HackRead

Threat Score
70/100

Date Published: 2025-12-23

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Jamf Threat Labs uncovered MacSync Stealer, a macOS infostealer distributed as a notarized, code-signed 'zk-call' installer that uses a fraudulent Developer Team ID (GNJLS3UYZ4) and an installer named zk-call-messenger-installer-3.9.2-lts.dmg; the malware stealthily throttles activity, logs runs, and attempts to harvest the system login.keychain-db (including prompting for the system password), prompting Apple to revoke the certificate.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.