macOS Trojan Upgrades: Spreading through Signed App, Encrypting Users Face More Covert Risk
BlockBeats News, December 23, SlowMist Chief Security Officer 23pds shared a post stating that the MacSync Stealer malware active on the macOS platform has undergone significant evolution, with user assets already being stolen. The article shared by him mentioned that from earlier reliance on "drag-and-drop to Terminal" and "ClickFix" and other low-threshold inducement methods, it has upgraded to code signing and through Apple notarized Swift applications, significantly improving its stealthiness.
Researchers found that this sample is being spread in the form of a disk image named zk-call-messenger-installer-3.9.2-lts.dmg, disguised as instant messaging or utility applications to induce users to download. Unlike before, the new version no longer requires any terminal operation by the user but is pulled and executed by a built-in Swift helper from a remote server to complete the information theft process.
This malware has been code signed and notarized by Apple, with the developer team ID being GNJLS3UYZ4, and the related hash has not been revoked by Apple during analysis. This means that it has a higher "trust level" under macOS's default security mechanisms, making it easier to bypass user vigilance. Research also found that the DMG file is unusually large, containing decoy files related to LibreOffice PDFs, among others, to further reduce suspicion.
Security researchers pointed out that such information-stealing trojans often target browser data, account credentials, and cryptocurrency wallet information. As malware begins to systematically abuse Apple's signing and notarization mechanism, cryptocurrency users in the macOS environment are facing an increasing risk of phishing and private key leaks.
Users are strongly advised to ensure that threat prevention and advanced threat control are enabled in Jamf for Mac and set to blocking mode to defend against these latest variants of information-stealing malware.
You may also like

Cybersecurity Firm Warns of Shai-Hulud 3.0 Threatening the NPM Ecosystem
Key Takeaways SlowMist’s CISO has issued a warning about Shai-Hulud 3.0, a significant threat targeting the NPM ecosystem…

SlowMist Warns of Return of Shai-Hulud 3.0 Supply Chain Attack
Key Takeaways SlowMist’s Chief Information Security Officer alerted the community about the resurgence of Shai-Hulud 3.0, an advanced…

Hackers Exploit Rainbow Six Siege Servers, Ubisoft Responds
Key Takeaways Hackers successfully breached Rainbow Six Siege, distributing enormous amounts of in-game currency. Players discovered unexpected changes…

Trust Wallet Investigates Browser Extension Security Incident
Key Takeaways A recent security incident in Trust Wallet’s browser extension has affected 2,596 wallets, leading to the…

Trust Wallet Users Experience $7 Million Loss Due to Hacked Chrome Extension
Key Takeaways Trust Wallet faced a significant security breach affecting its Chrome extension, resulting in over $7 million…

Trust Wallet Browser Extension Security Incident Leads to Losses
Key Takeaways Trust Wallet identified a significant security breach in its browser extension version 2.68. Approximately over $6…

Trust Wallet Hack Results in $3.5 Million Loss for Major Wallet Holder
Key Takeaways A significant Trust Wallet hack led to the theft of $3.5 million from an inactive wallet.…

Social Engineering in the Crypto Universe: Safeguarding Your Assets in 2025
Key Takeaways Social engineering, a psychological manipulation tactic, has been the leading cause of crypto asset theft in…

Crypto Advice for Newcomers, Veterans, and Skeptics in 2026
Key Takeaways Newcomers should learn about the fundamentals of crypto and blockchain technology before investing. Experimenting with crypto…

Philippines Cracks Down on Unlicensed Crypto Exchanges: Coinbase and Gemini Blocked
Key Takeaways The Philippine government is increasing regulatory oversight on cryptocurrency exchanges, requiring local licenses for operations. Internet…

Nofx’s Two-Month Journey from Stardom to Scandal: The Open Source Dilemma
Key Takeaways Nofx’s rise and fall in two months highlights inherent challenges in open source projects. A transition…

Enhancing the Future of Cryptocurrency Exchange: Understanding the Landscape
Key Takeaways Cryptocurrency exchange platforms are pivotal for digital currency transactions, offering diverse services tailored to user needs.…

The Evolution of Cryptocurrency Exchanges and the Role of WEEX
Key Takeaways Cryptocurrency exchanges like WEEX play a crucial role in the digital asset trading ecosystem by providing…

The Deepfake Reckoning: Why Crypto’s Next Security Battle Will Be Against Synthetic Humans
Key Takeaways The rise of generative AI and deepfakes poses a significant threat to digital identity verification in…

Rejecting the "Security Theater": Wallet Security is Entering the Era of Verifiability

The Future of Cryptocurrency Exchange: A Look into WEEX and Beyond
Key Takeaways Cryptocurrency exchanges play a crucial role in the digital asset marketplace. WEEX focuses on offering secure…

Weex: Exploring the Trends and Future of Cryptocurrency Exchanges
Key Takeaways: The dynamic landscape of cryptocurrency exchanges underscores the importance of adaptability and innovation. WEEX stands as…

Enhanced Vision of Digital Exchange Platforms
Key Takeaways The landscape of cryptocurrency exchange platforms is ever-evolving with technological advancements and market demands. The importance…
Cybersecurity Firm Warns of Shai-Hulud 3.0 Threatening the NPM Ecosystem
Key Takeaways SlowMist’s CISO has issued a warning about Shai-Hulud 3.0, a significant threat targeting the NPM ecosystem…
SlowMist Warns of Return of Shai-Hulud 3.0 Supply Chain Attack
Key Takeaways SlowMist’s Chief Information Security Officer alerted the community about the resurgence of Shai-Hulud 3.0, an advanced…
Hackers Exploit Rainbow Six Siege Servers, Ubisoft Responds
Key Takeaways Hackers successfully breached Rainbow Six Siege, distributing enormous amounts of in-game currency. Players discovered unexpected changes…
Trust Wallet Investigates Browser Extension Security Incident
Key Takeaways A recent security incident in Trust Wallet’s browser extension has affected 2,596 wallets, leading to the…
Trust Wallet Users Experience $7 Million Loss Due to Hacked Chrome Extension
Key Takeaways Trust Wallet faced a significant security breach affecting its Chrome extension, resulting in over $7 million…
Trust Wallet Browser Extension Security Incident Leads to Losses
Key Takeaways Trust Wallet identified a significant security breach in its browser extension version 2.68. Approximately over $6…
Popular coins
Latest Crypto News
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Services:support@weex.com