The post User assets already stolen as new MacSync variant bypasses macOS security appeared on BitcoinEthereumNews.com. While reviewing the detections of its inThe post User assets already stolen as new MacSync variant bypasses macOS security appeared on BitcoinEthereumNews.com. While reviewing the detections of its in

User assets already stolen as new MacSync variant bypasses macOS security

While reviewing the detections of its in-house YARA rules, Jamf Threat Labs claims it observed a signed and notarized stealer that did not follow the typical execution chains seen in the past. 

According to 23pds from Slowmist, this stealer is a new variant of the MacSync variant famous for bypassing macOS security. 

Slowmist claims user info already stolen 

In an X post, Slowmist’s Chief Information Security Officer, 23pds claimed that there is a new variant of the MacSync that bypasses the macOS gatekeeper security system, and it has already hijacked the information of many users. 

According to 23pds, to evade detection, the variant employs techniques like file inflation, network connection verification and self-destruct scripts after execution. It can reportedly steal sensitive data like iCloud keychains, browser passwords, and crypto wallets. 

The warning came attached to a blog from Jamf Threat Labs, reporting that this is not its first contact with MacSync. 

The macOS-targeted information stealer malware reportedly first emerged in April 2025 as “Mac.C”, developed by a threat actor known as “Mentalpositive”. It was rebranded to MacSync shortly after, which it quickly gained traction among cybercriminals.

To protect yourself from it, only download apps from the Mac App Store or trusted developer websites, keep your macOS and apps updated, use reputable antivirus/endpoint security tools that detect macOS threats, and be cautious with unexpected .dmg files or installers, especially those promising crypto-related or messaging tools.

Is there a new MacSync malware? 

The sample in question reportedly looked highly similar to past variants of the increasingly active MacSync Stealer malware but was revamped in its design. It differed from earlier MacSync Stealer variants that primarily rely on drag-to-terminal or ClickFix-style techniques, as it employs a more deceptive, hands-off approach. 

The sample is reportedly delivered as a code-signed and notarized Swift application within a disk image named zk-call-messenger-installer-3.9.2-lts.dmg, distributed via https://zkcall.net/download. 

That removes the need for any direct terminal interaction. Instead, the dropper retrieves an encoded script from a remote server and executes it via a Swift-built helper executable

Jamf Threat Labs also observed the Odyssey infostealer adopting similar distribution methods in recent variants. They expressed surprise that the familiar right-click open instruction is still present in the new sample, even though the executable is signed and does not require this step.

“After inspecting the Mach-O binary, which is a universal build, we confirmed that it is both code-signed and notarized. The signature is associated with the Developer Team ID GNJLS3UYZ4,” they claimed. 

They made sure to verify the code directory hashes against Apple’s revocation list, and at the time of analysis, said none had been revoked.

Another notable observation made is the unusually large size of the disk image (25.5MB), which they said appears to be inflated by decoy files embedded within the app bundle. 

At the time of analysis, some of the samples uploaded to VirusTotal were detected by only one antivirus engine, while others were flagged by up to thirteen. After confirming that the Developer Team ID was used to distribute malicious payloads, Jamf Threat Labs reported it to Apple. Since then, the associated certificate has been revoked.

Join Bybit now and claim a $50 bonus in minutes

Source: https://www.cryptopolitan.com/new-macsync-variant-bypasses-macos-security/

Market Opportunity
Housecoin Logo
Housecoin Price(HOUSE)
$0.002032
$0.002032$0.002032
+6.89%
USD
Housecoin (HOUSE) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

BitGo expands its presence in Europe

BitGo expands its presence in Europe

The post BitGo expands its presence in Europe appeared on BitcoinEthereumNews.com. BitGo, global leader in digital asset infrastructure, announces a significant expansion of its presence in Europe. The company, through its subsidiary BitGo Europe GmbH, has obtained an extension of the license from BaFin (German Federal Financial Supervisory Authority), allowing it to offer regulated cryptocurrency trading services directly from Frankfurt, Germany. This move marks a decisive step for the European digital asset market, offering institutional investors the opportunity to access secure, regulated cryptocurrency trading integrated with advanced custody and management services. A comprehensive offering for European institutional investors With the extension of the license according to the MiCA (Markets in Crypto-Assets) regulation, initially obtained in May 2025, BitGo Europe expands the range of services available for European investors. Now, in addition to custody, staking, and transfer of digital assets, the platform also offers a spot trading service on thousands of cryptocurrencies and stablecoins. Institutional investors can now leverage BitGo’s OTC desk and a high-performance electronic trading platform, designed to ensure fast, secure, and transparent transactions. Aggregated access to numerous liquidity sources, including leading market makers and exchanges, allows for trading at competitive prices and high-quality executions. Security and Regulation at the Core of BitGo’s Strategy According to Brett Reeves, Head of European Sales and Go Network at BitGo, the goal is clear: “We are excited to strengthen our European platform and enable our clients to operate smoothly, competitively, and securely.§By combining our institutional custody solution with high-performance trading execution, clients will be able to access deep liquidity with the peace of mind that their assets will remain in cold storage, under regulated custody and compliant with MiCA.” The security of digital assets is indeed one of the cornerstones of BitGo’s offering. All services are designed to ensure that investors’ assets remain protected in regulated cold storage, minimizing operational and counterparty risks.…
Share
BitcoinEthereumNews2025/09/18 04:28
LayerZero Foundation initiates buyback of 50 million ZRO from early backers

LayerZero Foundation initiates buyback of 50 million ZRO from early backers

The post LayerZero Foundation initiates buyback of 50 million ZRO from early backers appeared on BitcoinEthereumNews.com. Key Takeaways LayerZero Foundation has initiated a buyback for 50 million ZRO tokens. The buyback targets early investors who supported LayerZero during its early development stages. LayerZero Foundation, the non-profit entity overseeing the development of the LayerZero blockchain interoperability protocol, today initiated a buyback of 50 million ZRO tokens from early backers. The buyback targets tokens held by initial investors who provided funding during the project’s early development phases. Token buybacks in crypto are typically used to reduce circulating supply and signal long-term confidence in the protocol. ZRO launched in June 2024 with an initial fully diluted valuation of around $3.0 billion. The foundation distributed 8.5% of the token supply through an airdrop on launch day to bootstrap community participation. LayerZero’s protocol connects over 50 blockchains and has facilitated more than 100 million cross-chain messages since launch, enhancing liquidity across decentralized applications. Source: https://cryptobriefing.com/layerzero-zro-token-buyback-early-backers-2025/
Share
BitcoinEthereumNews2025/09/23 10:36
Top political stories of 2025: The Villar family’s business and political setbacks

Top political stories of 2025: The Villar family’s business and political setbacks

Rappler's Dwight de Leon recaps the challenges faced in 2025 by one of the Philippines' wealthiest families
Share
Rappler2025/12/25 09:00