New MacSync malware dropper evades macOS Gatekeeper checks
ID: e8257b7c-d1f3-5c0f-b00c-6abdccf9df2c
STIX ID: report--e8257b7c-d1f3-5c0f-b00c-6abdccf9df2c
Feed Name: Bleeping Computer
Jamf analysis describes a new MacSync (Mac.C) macOS infostealer distributed via a code-signed, notarized Swift app inside a disk image (zk-call-messenger-installer-3.9.2-lts.dmg) from zkcall.net that bypassed Gatekeeper. The variant includes evasion techniques (inflated DMG with decoy PDFs, wiping execution scripts, internet-connectivity checks), steals iCloud keychain, browser credentials, crypto wallet data and files, and was linked to the actor 'Mentalpositive'; the signing certificate (Developer Team ID GNJLS3UYZ4) was revoked after reporting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
