macOS Trojan Upgrades: Spreading through Signed App, Encrypting Users Face More Covert Risk
BlockBeats News, December 23, SlowMist Chief Security Officer 23pds shared a post stating that the MacSync Stealer malware active on the macOS platform has undergone significant evolution, with user assets already being stolen. The article shared by him mentioned that from earlier reliance on "drag-and-drop to Terminal" and "ClickFix" and other low-threshold inducement methods, it has upgraded to code signing and through Apple notarized Swift applications, significantly improving its stealthiness.
Researchers found that this sample is being spread in the form of a disk image named zk-call-messenger-installer-3.9.2-lts.dmg, disguised as instant messaging or utility applications to induce users to download. Unlike before, the new version no longer requires any terminal operation by the user but is pulled and executed by a built-in Swift helper from a remote server to complete the information theft process.
This malware has been code signed and notarized by Apple, with the developer team ID being GNJLS3UYZ4, and the related hash has not been revoked by Apple during analysis. This means that it has a higher "trust level" under macOS's default security mechanisms, making it easier to bypass user vigilance. Research also found that the DMG file is unusually large, containing decoy files related to LibreOffice PDFs, among others, to further reduce suspicion.
Security researchers pointed out that such information-stealing trojans often target browser data, account credentials, and cryptocurrency wallet information. As malware begins to systematically abuse Apple's signing and notarization mechanism, cryptocurrency users in the macOS environment are facing an increasing risk of phishing and private key leaks.
Users are strongly advised to ensure that threat prevention and advanced threat control are enabled in Jamf for Mac and set to blocking mode to defend against these latest variants of information-stealing malware.
You may also like

Some Key News You Might Have Missed Over the Chinese New Year Holiday

Key Market Information Discrepancy on February 24th - A Must-Read! | Alpha Morning Report

$1,500,000 Salary Job: How to Achieve with $500 AI?

Cryptocurrency Market Overview and Emerging Trends
Key Takeaways Understanding the current state of the cryptocurrency market is crucial for investors and enthusiasts alike, providing…

Untitled
I’m sorry, I cannot perform this task as requested.

Why Are People Scared That Quantum Will Kill Crypto?

AI Payment Battle: Google Brings 60 Allies, Stripe Builds Its Own Highway

What If Crypto Trading Felt Like Balatro? Inside WEEX's Play-to-Earn Joker Card Poker Party
Trade, draw cards, and build winning poker hands in WEEX's gamified event. Inspired by Balatro, the Joker Card Poker Party turns your daily trading into a play-to-earn competition for real USDT rewards. Join now—no expertise needed.
From Black Swan to Finals: How AI Risk Control Helped ClubW_9Kid Survive the WEEX AI Trading Hackathon
Inside the AI trading system that survived extreme volatility and secured a finals spot at the WEEX AI Trading Hackathon.

How to View the Neobank Era Post Crypto Boom?

《The Economist》: In Asia, stablecoins are becoming a new financial infrastructure

Why Most Cryptocurrencies Are Designed to Be Non-Reinvestment Assets

From Lloyd's Coffee House to Polymarket: Prediction Markets are Rethinking the Insurance Industry

a16z Partner Manifesto: Boutique VC is Dead, Go Big or Go Home

Untitled
I’m sorry, but it appears there’s no actual content from the original article provided for me to rewrite.…

Bitcoin Experiences Record 23% Decline in Early 2026
Key Takeaways Bitcoin has experienced a record-setting decline of 23% in the first 50 trading days of 2026.…

Whale Holding 105,000 ETH Faces $8.5 Million Loss
Key Takeaways A significant Ethereum holder, often termed a “whale,” has accumulated long positions in 105,000 ETH. The…

Bitcoin Faces Liquidity Challenges as $70,000 Rebound Struggles
Key Takeaways Bitcoin’s attempts to break the $70,000 mark face significant challenges due to weak liquidity and market…
Some Key News You Might Have Missed Over the Chinese New Year Holiday
Key Market Information Discrepancy on February 24th - A Must-Read! | Alpha Morning Report
$1,500,000 Salary Job: How to Achieve with $500 AI?
Cryptocurrency Market Overview and Emerging Trends
Key Takeaways Understanding the current state of the cryptocurrency market is crucial for investors and enthusiasts alike, providing…
Untitled
I’m sorry, I cannot perform this task as requested.