New MacSync malware dropper evades macOS Gatekeeper checks
嗯,用户让我帮忙总结一篇文章的内容,控制在一百个字以内,而且不需要特定的开头。首先,我需要理解文章的主要内容。看起来这篇文章讲的是MacSync信息窃取器的新变种,它通过一个经过数字签名和公证的Swift应用程序传播到macOS系统。 接下来,我要提取关键点:数字签名、公证、Swift应用、绕过Gatekeeper、窃取信息类型以及作者的动机。这些是用户可能关心的重点。 然后,我需要将这些信息浓缩到一百个字以内,同时保持语句通顺。可能的结构是先说明变种如何传播,接着提到它的技术手段和影响。 最后,检查是否符合用户的要求:不使用特定开头,直接描述内容,并且字数控制在限制内。确保没有遗漏重要信息,同时语言简洁明了。 </think> MacSync信息窃取器新变种通过数字签名和公证的Swift应用传播至macOS系统,绕过Gatekeeper安全检查。该恶意软件可窃取iCloud密钥链、浏览器密码、系统元数据及加密钱包数据等信息。 2025-12-22 20:45:19 Author: www.bleepingcomputer.com(查看原文) 阅读量:1 收藏

New MacSync malware dropper evades macOS Gatekeeper checks

The latest variant of the MacSync information stealer targeting macOS systems is delivered through a digitally signed, notarized Swift application.

Security researchers at Apple device management platform Jamf say that the distribution method constitutes a significant evolution from past iterations that used less sophisticated "drag-to-Terminal" or ClickFix tactics.

"Delivered as a code-signed and notarized Swift application within a disk image named zk-call-messenger-installer-3.9.2-lts.dmg, distributed via https://zkcall.net/download, it removes the need for any direct terminal interaction," the researchers say in a report today.

Wiz

Valid digital signature
Valid digital signature and notarization
Source: Jamf

At the time of the analysis, Jamf says that the latest MacSync variant had a valid signature and could bypass checks from Gatekeeper, the security system in macOS.

"After inspecting the Mach-O binary, which is a universal build, we confirmed that it is both code-signed and notarized. The signature is associated with the Developer Team ID GNJLS3UYZ4," Jamf explains.

However, following a direct report of the certificate to Apple, it has now been revoked.

The malware is delivered on the system through a dropper in encoded form. After decoding the payload, researchers discovered the usual signs of the MacSync Stealer.

The deobfuscated payload
The deobfuscated payload
Source: Jamf

The researchers noted that the stealer features several evasion mechanisms, including inflating the DMG file to 25.5MB by embedding decoy PDFs, wiping the scripts used in the execution chain, and performing internet connectivity checks before execution to evade sandboxed environments.

The inflated disk image contents
The inflated disk image contents
Source: Jamf

The stealer emerged in April 2025 as Mac.C by a threat actor named ‘Mentalpositive’. It gained traction by July, joining the less crowded but still profitable space of macOS stealers alongside AMOS and Odyssey.

A previous analysis of Mac.C by MacPaw Moonlock indicates that it can steal iCloud keychain credentials, passwords stored on web browsers, system metadata, cryptocurrency wallet data, and files from the filesystem.

Interestingly, in an interview that Mentalpositive gave to researcher g0njxa in September, the malware author stated that the introduction of a tighter app notarization policy in macOS 10.14.5 and later had the strongest influence on their development plans, which is reflected in the latest versions caught in the wild.

tines

Break down IAM silos like Bitpanda, KnowBe4, and PathAI

Broken IAM isn't just an IT problem - the impact ripples across your whole business.

This practical guide covers why traditional IAM practices fail to keep up with modern demands, examples of what "good" IAM looks like, and a simple checklist for building a scalable strategy.


文章来源: https://www.bleepingcomputer.com/news/security/new-macsync-malware-dropper-evades-macos-gatekeeper-checks/
如有侵权请联系:admin#unsafe.sh