A new variant of the MacSync Stealer malware has emerged, leveraging a code-signed and notarized Swift application to bypass Apple's built-in malware protections. Security researchers from Jamf identified that this variant is distributed as a disk image containing a Swift app, which is both signed and notarized, allowing it to evade standard macOS security checks. Once executed, the app retrieves an encoded script from a remote server and runs it via a helper executable, effectively installing the stealer without requiring the user to interact with the Terminal or bypass typical security warnings.
This approach marks a significant evolution from previous MacSync Stealer tactics, which relied on social engineering to trick users into running commands in Terminal or using "ClickFix"-style techniques. The new method removes the need for direct user intervention, increasing the likelihood of successful infections. The installer was observed to be distributed via a website and, at the time of analysis, its code signature had not been revoked by Apple. Researchers also noted that similar distribution methods are being adopted by other Mac-focused infostealers, indicating a broader trend in macOS malware delivery.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
On a macOS system, researchers observed a MacSync Stealer infection involving a DMG download from zkcall.net and subsequent traffic to domains including obsidiangate.space and focusgroovy.com. The incident was documented with malware samples and a sanitized packet capture showing command-and-control and exfiltration activity.
After Jamf reported the abuse, Apple revoked the Developer Team ID used to sign the malicious dropper. This action removed the certificate that had allowed the fake installer to appear trusted and pass notarization checks.
Jamf Threat Labs analyzed the new variant, linked it to Developer Team ID GNJLS3UYZ4, and documented its evasion and credential-stealing behavior, including theft of keychain, browser, wallet, and system data. The research also tied the malware to infrastructure such as focusgroovy.com and gatemaden.space and attributed the stealer to the threat actor Mentalpositive.
A new MacSync Stealer variant began circulating as a code-signed and Apple-notarized Swift application delivered in a disk image such as "zk-call-messenger-installer-3.9.2-lts.dmg" from zkcall.net. The malware shifted from earlier terminal-based infection steps to a quieter second-stage download and execution flow designed to evade Gatekeeper and reduce user interaction.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 19 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
8 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcecsoonline.com
Open sourcecybersecuritynews.com
Open sourcehackread.com
Open sourcemalware-traffic-analysis.net
Open source9to5mac.com
Open sourcebleepingcomputer.com
Open sourcejamf.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.