macOS Trojan Upgrades: Spreading through Signed App, Encrypting Users Face More Covert Risk
BlockBeats News, December 23, SlowMist Chief Security Officer 23pds shared a post stating that the MacSync Stealer malware active on the macOS platform has undergone significant evolution, with user assets already being stolen. The article shared by him mentioned that from earlier reliance on "drag-and-drop to Terminal" and "ClickFix" and other low-threshold inducement methods, it has upgraded to code signing and through Apple notarized Swift applications, significantly improving its stealthiness.
Researchers found that this sample is being spread in the form of a disk image named zk-call-messenger-installer-3.9.2-lts.dmg, disguised as instant messaging or utility applications to induce users to download. Unlike before, the new version no longer requires any terminal operation by the user but is pulled and executed by a built-in Swift helper from a remote server to complete the information theft process.
This malware has been code signed and notarized by Apple, with the developer team ID being GNJLS3UYZ4, and the related hash has not been revoked by Apple during analysis. This means that it has a higher "trust level" under macOS's default security mechanisms, making it easier to bypass user vigilance. Research also found that the DMG file is unusually large, containing decoy files related to LibreOffice PDFs, among others, to further reduce suspicion.
Security researchers pointed out that such information-stealing trojans often target browser data, account credentials, and cryptocurrency wallet information. As malware begins to systematically abuse Apple's signing and notarization mechanism, cryptocurrency users in the macOS environment are facing an increasing risk of phishing and private key leaks.
Users are strongly advised to ensure that threat prevention and advanced threat control are enabled in Jamf for Mac and set to blocking mode to defend against these latest variants of information-stealing malware.
You may also like

Interview with Hyperliquid Founder Jeff Yan: Crypto and DeFi Are in Our DNA, Never Compromising on Trust

$1 Billion Free Lottery, Kalshi Launches Prediction Challenge

SlowMist: Is it Really Safe to Entrust Your Money to an AI Agent like "Lobster"?

Regulation, Insiderism, and Essence: The Story Behind Kalshi's $20 Billion Valuation

You Have Been Training Google's AI for Free for 15 Years, and You Didn't Even Know
Best AI Crypto Trading Bot? Inside the AI Trading System That Ranked Top 3 on WEEX
Discover the best AI crypto trading bot on WEEX. Learn how AI trading works, how to trade automatically, and why this system stands out among top AI trading apps.

How to Trade Cryptocurrency Without App Store: Instant Browser Crypto Trading on WEEX
Trade crypto instantly without downloading an app. Use WEEX H5 to access spot and futures trading directly in your browser with fast execution, real-time risk control, and seamless experience across mobile, tablet, and desktop. Supports Bitcoin, Ethereum, and more.

From OKX to Bybit, exchanges are changing tires on the highway at high speed

A Brief History and Future of Perpetual Contracts

AI Agent Gets ID and Wallet on the Same Day | Rewire News Morning Brief

IOSG: Power Flexibility Paradigm Shift: From Macro Assets to Distributed Intelligence Layer

Murata 35% Price Increase Explained: A Capacitor that Gives AI Empire a Cold

MiniMax: A Henan County Youth and His 300 Billion

From Abandoned Project to Sky-High Target, Mastercorp Acquires BVNK for $1.8 Billion

Is Polymarket's Pricing Accurate? I Simulated a Crisis with 200 Agents to Find Out

A Decade of Regulation Finally Clarified, Victory for Crypto-Native Logic

The United States Establishes the "Five Categories Law" for Cryptographic Assets: A Summary to Understand the New Regulatory Framework

Morning Report | Mastercard plans to acquire BVNK for up to $1.8 billion; Solana Foundation launches aggregator Tokens on Solana; Bitcoin sees its first 8 consecutive rises in four years
Interview with Hyperliquid Founder Jeff Yan: Crypto and DeFi Are in Our DNA, Never Compromising on Trust
$1 Billion Free Lottery, Kalshi Launches Prediction Challenge
SlowMist: Is it Really Safe to Entrust Your Money to an AI Agent like "Lobster"?
Regulation, Insiderism, and Essence: The Story Behind Kalshi's $20 Billion Valuation
You Have Been Training Google's AI for Free for 15 Years, and You Didn't Even Know
Best AI Crypto Trading Bot? Inside the AI Trading System That Ranked Top 3 on WEEX
Discover the best AI crypto trading bot on WEEX. Learn how AI trading works, how to trade automatically, and why this system stands out among top AI trading apps.