Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

New MacSync Stealer Malware Attacking macOS Users Using Digitally Signed Apps

## Cybersecurity: MacSync Stealer Malware Update

Cybersecurity: MacSync Stealer Malware Update

A newly updated version of the MacSync Stealer malware is targeting macOS users via digitally signed and notarized applications, indicating a significant change in the delivery method of this threat.

The recent variant operates silently in the background, contrasting with older versions that required user interaction with Terminal. The malware masquerades as a legitimate installer, distributed via a fraudulent website under the filename zk-call-messenger-installer-3.9.2-lts.dmg. Upon installation, it executes a hidden script to extract sensitive information from the victim's system.

The malware is developed as a Swift application and is signed with Apple's Developer Team ID GNJLS3UYZ4. This signing allows it to bypass macOS's initial security alerts for untrusted applications. At the time of discovery, Apple's certificate for this malware had not been revoked, facilitating its installation without triggering security warnings. The disk image file is 25.5MB, containing fake PDF files related to LibreOffice to enhance its appearance as legitimate software.

When submitted to VirusTotal, some antivirus engines identified it as a generic downloader linked to other malware families. Jamf analysts discovered this malware while monitoring their detection systems, noting its deviation from previous MacSync campaigns, which typically utilized drag-to-terminal or ClickFix methods.

The recent variant operates silently in the background, contrasting with older versions that required user interaction with Terminal.
Hazel Caldwell · Thehackingpost

Following confirmation of the threat, Jamf Threat Labs reported the malicious Developer Team ID to Apple, leading to the subsequent revocation of the certificate.

Swift-Based Execution and Payload Delivery

The malware employs a Swift-based helper program named runtimectl, which manages the infection process. Upon execution, it verifies the system's internet connection using the checkInternet() function. If connected, it downloads a second-stage payload from a specified URL using a curl command and saves it to /tmp/runner. This script is verified as a valid shell script before execution.

The malware removes the com.apple.quarantine flag and sets file permissions to make the script executable. Log files are created at ~/Library/Logs/UserSyncWorker.log, and tracking files are stored in ~/Library/Application Support/UserSyncWorker/ to monitor activity and prevent frequent executions. The malware includes a rate-limiting mechanism, ensuring it runs only once every 3600 seconds.

Advertisement

Upon execution, the /tmp/runner file is deleted to eliminate traces, and the malware connects to a command-and-control server for downloading additional payloads.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories