logo

New MacSync malware dropper evades macOS Gatekeeper checks

ID: e8257b7c-d1f3-5c0f-b00c-6abdccf9df2c

STIX ID: report--e8257b7c-d1f3-5c0f-b00c-6abdccf9df2c

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-12-22

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Jamf analysis describes a new MacSync (Mac.C) macOS infostealer distributed via a code-signed, notarized Swift app inside a disk image (zk-call-messenger-installer-3.9.2-lts.dmg) from zkcall.net that bypassed Gatekeeper. The variant includes evasion techniques (inflated DMG with decoy PDFs, wiping execution scripts, internet-connectivity checks), steals iCloud keychain, browser credentials, crypto wallet data and files, and was linked to the actor 'Mentalpositive'; the signing certificate (Developer Team ID GNJLS3UYZ4) was revoked after reporting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.