logo

Reworked MacSync Stealer Adopts Quieter Installation Process

ID: 1eb6ef8d-1f0e-5bed-b825-e3c9b59b79be

STIX ID: report--1eb6ef8d-1f0e-5bed-b825-e3c9b59b79be

Feed Name: Infosecurity Magazine (News)

Threat Score
68/100

Date Published: 2025-12-23

Date Updated: 2026-04-22

...
...

Jamf Threat Labs discovered a reworked MacSync Stealer variant for macOS that is distributed as a code-signed, notarized Swift application inside a deceptive disk image. The dropper performs connectivity and timing checks, downloads an encoded payload via an obfuscated curl invocation, removes quarantine attributes, executes largely in memory, and cleans up traces; the associated developer certificate was reported to Apple and revoked.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.