MacSync Stealer: The silent malware that bypasses Mac security

  • MacSync Stealer disguises itself as a Swift app signed and notarized by Apple to bypass Gatekeeper and XProtect.
  • The installer acts as a dropper: it is distributed in inflated DMGs, analyzes the system, and downloads a remote payload.
  • The MacSync core steals credentials and sensitive data and offers command and control and remote control capabilities.
  • Apple has revoked the certificates involved, but experts warn of a trend toward the abuse of signed executables in macOS.

MacSync Stealer Malware on macOS

The ecosystem of Mac computers It has encountered a threat that is already playing in a different league: MacSync Stealer, a malware specialized in stealing information that infiltrates computers leveraging Apple's own trusted systemsFar from the shoddy viruses of the past, this malicious software presents itself as a legitimate and reliable application, with a valid developer signature and a notarized verification process, also in Spain and the rest of Europe, as analyses show. cyberattacks on Mac and Linux.

In its most recent variants, this family of malicious code It runs as an app written in Swift, signed and notarized by AppleThis allows it to bypass many of macOS's initial security measures, including mechanisms like Gatekeeper and XProtect. This significant leap makes early detection more difficult and opens the door to... silent leaks of personal and corporate data both in domestic and professional environments.

What is MacSync Stealer and how has it evolved in macOS?

In his first appearances, The infection relied on techniques that required explicit user actionsMethods similar to ClickFix or the classic "copy and paste" commands in the Terminal to run malicious scripts were used. This approach required a greater degree of manual interaction, giving the user more opportunity to suspect something was amiss and stop the installation before the damage became more extensive.

The analyzes of Jamf Threat LabsThe leading Apple device security lab describes a rather different situation in the latest variant. According to their reports, MacSync Stealer has given a a leap towards a much more automated and silent infection modelminimizing visible signs to the victim and relying on the trust generated by Apple's signature and notarization.

The trick is that the first phase of the attack is presented as a Application developed in Swift, with legitimate developer ID, valid code signature, and passed notarizationFor the operating system and for most users, this combination is synonymous with reliable software, when in reality it is the first link in a carefully designed infection chain.

In many cases, the threat arrives disguised as messaging service, productivity tool, or synchronization utilityWith a name, icon, and descriptions that sound completely harmless, this facade further reduces initial suspicions—a particularly worrying detail in European offices, public administrations, and companies where the Mac has become established as a daily work tool.

Signed Swift application that distributes MacSync

A Swift installer that bypasses Gatekeeper and acts as a dropper

The campaign described by Jamf shows that the first component of the threat functions as a dropper written in SwiftA seemingly legitimate installer whose real purpose is to prepare the ground and download the actual malicious code from a remote server. Initially, the Mach-O binary contained in this app... It appears signed and notarized, associated with a real developer Team IDTherefore, it easily passes the initial Gatekeeper checks.

In one of the cases analyzed, the dropper was distributed as a DMG disk image with messaging application nameunder names such as “zk-call-messenger-installer-3.9.2-lts.dmg” and hosted on a domain prepared for the campaign. The installer presents itself to the user as a supposed calling and messaging tool, so that Simply double-click to run it, without the complicated steps of older infections.

Even if the package is signed, in some scenarios attackers add Instructions to force the user to right-click and select "Open"This is a classic trick to bypass additional macOS warnings when the app doesn't come from the Mac App Store. This small detail, which many overlook, should raise red flags, especially if the software comes from an obscure website.

Once the user starts the application, the dropper performs a series of environmental checks before moving on to the second phaseAmong other steps, it verifies that the computer has a stable internet connection, checks certain system conditions, and, in some cases, waits for a minimum execution time period close to 3600 seconds so that their behavior does not appear too immediate or suspicious.

When the conditions set by the attackers are met, the program connects to a remote command and control server to download an encoded script or payload, usually in Base64, containing the MacSync Stealer core. At this stage, the code responsible for steal information and maintain control over the compromised Mac, while the initial installer is limited to serving as a Trojan horse.

MacSync Stealer Attack Phased Structure

Inflated DMG files, decoy files, and download changes to evade detection

One of the aspects that has most caught the attention of researchers is the use of large disk images filled with decoy filesThe DMG associated with this installer is around 25,5 MB, an unusually high volume for what, on the surface, appears to be a simple messaging application or light utility.

According to Jamf Threat Labs, this weight is achieved inflating the package with irrelevant documents, such as PDFs or other embedded files that contribute nothing to the app's functionality. That mix of filler content with the actual component This complicates the automated analysis performed by antivirus and security solutions.who must process a larger volume of data and distinguish what is legitimate and what is not.

After mounting the disk image and running the application, the dropper starts a local environment scanning to check everything from connectivity to certain system parameters. Only when it is clear that the scenario is suitable does it contact the remote infrastructure to download the second module. In many cases, the loads are They primarily run in memory, leaving a minimal footprint on disk. and further complicating subsequent forensic detection.

The code downloaded in this second phase corresponds to MacSync, an evolution of an earlier family known as Mac.cIndependent investigations indicate that this agent is developed in Go and has a range of capabilities that goes far beyond simply stealing passwords, following the trend of other modern threats targeting macOS.

To top it all off, the attackers even fine-tune their download commands used in the processThe use of tools such as curl It is done with less common parameter combinations —for example, by separating the typical string -fsSL on flags like -fL y -sSand incorporating options such as --noproxy— with the aim of evading detection rules based on repeated patterns and improve the reliability of the connection to their servers.

Inflated DMG disk image used by MacSync

From data thief to remote control platform

The heart of MacSync Stealer goes beyond the basic infostealer category: technical analyses describe a agent with full command and control (C2) capabilities, prepared to maintain persistent communication with the affected team and receive real-time instructions.

Among the functions attributed to this family, the following stand out: theft of credentials, browsing cookies, bank card data and cryptocurrency walletsas well as the exfiltration of all types of files of interest to the attackers. Access to information stored in the macOS Keychain Data from browsers like Safari, Chrome, or Firefox is already a very attractive set of targets for financial fraud campaigns and corporate espionage.

Another sensitive point is the ability to Install additional modules on demandThis modular approach allows the compromised team to become a kind of malicious "Swiss Army knife": today the emphasis may be on collecting passwords and tomorrow on logging keystrokes, encrypting files, moving laterally through a corporate network or deploying new remote access tools.

For users and businesses in Spain and the rest of Europe, this transition from a simple data thief to a flexible remote control platform This represents a significant leap in the level of risk. An infected Mac ceases to be merely a one-off source of stolen information and becomes gateway to enterprise networks, cloud services, or critical systems to which the device has access.

This scenario fits with a broader trend observed by various cybersecurity firms: the sustained increase in infostealers and modular Trojans targeting macOSThis is driven by the growing market share of Apple devices and the economic profile of their users, which makes them a particularly attractive target for online fraud.

Data theft and remote control on Mac with MacSync

Apple's response and the limits of automatic protection in macOS

Following warnings from Jamf Threat Labs and other security companies, Apple has revoked the code signing certificates associated with the Team ID used in the MacSync Stealer campaign.With this measure, the operating system stops trusting applications signed with that identifier and blocks new builds that attempt to use it to distribute malicious software.

In parallel, the company has updated its internal protection mechanisms, such as XProtect and Gatekeeperwith new detection rules and lists of known hashes and signatures. In current versions of macOS, these blacklists are updated frequently without user intervention, so it's key keep the system up to date and apply the available updates to benefit from those patches and improvements.

Even so, experts insist that the MacSync Stealer case illustrates a general trend of malware for macOS: attackers are increasingly trying to fit your code into signed and notarized executablesso that they appear to be completely legitimate and trustworthy applications. If they achieve this, the likelihood of the user receiving clear warnings is significantly reduced.

Reports from Jamf and other firms underscore that, even when Apple revokes compromised certificates, Cybercriminals can register new developer IDs and repeat the same strategy.by adapting small details to circumvent the newly added rules. This cat-and-mouse game forces the native macOS defenses to be supplemented with additional layers.

This context reinforces the idea that Safety cannot depend exclusively on automatic protectionsAlthough Gatekeeper, XProtect, and the notarization process have raised the bar considerably, attacks like the MacSync Stealer demonstrate that trust mechanisms can also be used against users when someone manages to slip their app into the verification chain.

Gatekeeper and XProtect vs. MacSync Stealer

Impact on Mac users in Spain and Europe and best practices for protection

The expansion of the Mac in offices, universities and homes in Spain and the rest of Europe macOS has become an increasingly attractive target for criminal groups. It's no longer a niche platform: more and more organizations are integrating macOS into their infrastructure, making threats like MacSync Stealer a major problem for the region.

Experts recommend strengthening both technical skills and daily habits. The first step, seemingly simple but fundamental, is Keep macOS and apps up to date and carrying out regular backupsBecause Apple frequently introduces new signatures and blocking rules for these types of threats, ignoring security updates leaves the door open to variants that have already been documented and patched.

Emphasis is also placed on the importance of limit software installation to the Mac App Store or well-known developersEven if the installer appears signed and notarized, that label is no longer an absolute guarantee of security, as this case demonstrates. Downloading apps from links received via email, messaging, or untrusted websites significantly increases the risk of infection.

Another key piece is Pay attention to the permissions each application requests.Access to the keychain, user documents, browser history, or accessibility features are permissions that should be granted sparingly, especially when dealing with free utilities of dubious origin. Many successful infections rely precisely on this. excessive permissions that the user himself accepted without reviewing.

In professional environments, especially within the European Union, it is advisable to complement Apple's defenses with security solutions specifically for macOSEDR tools and clear software download and installation policies are essential. These measures are especially relevant for companies subject to data protection regulations, where an incident of credential theft or information exfiltration can lead to penalties and a loss of trust.

Cybersecurity best practices for Mac users

Cyberattacks on Mac and Linux in Latin America
Related article:
Cyberattacks on Mac and Linux in Latin America: figures, most affected countries and lessons for Europe

Everything surrounding MacSync Stealer shows the extent to which the Mac malware is no longer a rarityAttackers rely on signed and notarized executables, inflate disk images with decoy files, download second-stage payloads from remote servers, and deploy agents capable of stealing data and maintaining remote control over computers. In this scenario, the old idea that "Macs are virus-free" is definitively outdated, and protection now involves combining Apple's native defenses with good usage practices and constant monitoring to prevent our computer from being the weakest link in the chain.


Add as preferred source