BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Notarized MacSync stealer evades Gatekeeper via a signed app

Code‑signed, notarized Swift app in inflated DMG delivers MacSync info‑stealer from zkcall[.]net; Apple revokes certificate

  • MacSync has a new variant delivered inside a code-signed, notarized Swift app in a DMG file hosted on zkcall[.]net/download.
  • The installer bypassed macOS protections by using a signed, notarized bundle and user prompts; Apple has revoked the signing certificate.
  • The Swift dropper enforces checks (connectivity, a ~3600‑second delay, quarantine removal) and fetches a Base64 payload decoded into the MacSync stealer.
  • Attackers used evasion tactics such as unusual curl flags, dynamic variables, and an inflated 25.5 MB DMG containing unrelated PDFs.

On Dec. 24, 2025, researchers at Jamf reported a new macOS information stealer variant delivered as a digitally signed, notarized Swift application inside a disk image named “zk-call-messenger-installer-3.9.2-lts.dmg” hosted at zkcall[.]net/download. The Malware impersonated a messaging installer to evade Apple protections; Apple has since revoked the code‑signing certificate. According to Jamf researcher Thijs Xhaflaire, this sample uses a more deceptive, hands‑off method than prior MacSync variants.

- Advertisement -

The Swift dropper performs multiple runtime checks before executing the payload. It verifies internet connectivity, enforces about a 3600‑second minimum execution interval, removes quarantine attributes, and validates files prior to launch. The dropper retrieves an encoded script via a helper component and decodes a Base64 payload that corresponds to MacSync.

“Notably, the curl command used to retrieve the payload shows clear deviations from earlier variants,” wrote the researcher, noting the use of split flags (-fL and -sS) and additional options like –noproxy (source). The changes and use of dynamically populated variables suggest altered fetching and validation behavior.

The decoded payload links MacSync to a rebranded form of Mac.c, and researchers at Moonlock Lab note that MacSync includes a Go‑based agent enabling remote command‑and‑control capabilities. Attackers also inflated the DMG to about 25.5 MB by embedding unrelated PDF files as an evasion tactic.

Definitions: Gatekeeper — Apple’s app verification feature that checks code signing and notarization. Notarized — a process where Apple scans an app for known malware and issues a notarization ticket. DMG — a macOS disk image file used to distribute software. Base64 — an encoding method that converts binary data to ASCII text for transport.

- Advertisement -

Similar tactics have been observed elsewhere: code‑signed DMGs mimicking Google Meet have carried other stealers such as Odyssey, while some campaigns still use unsigned images to deliver malware like DigitStealer. “This shift in distribution reflects a broader trend across the macOS malware landscape, where attackers increasingly attempt to sneak their malware into executables that are signed and notarized, allowing them to look more like legitimate applications,” the researchers stated (source).

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

New botnet targets Android TVs, IoT devices

A new Mirai-derived botnet called xlabs_v1 is targeting internet-exposed Android devices to build a...

Corning Stock Up 9% on $500M Nvidia Deal

Corning stock surged 9% to a record high after announcing a $500 million deal...

Bittrex Seeks $24M SEC Settlement Refund After Policy Shift

Defunct crypto exchange Bittrex is asking a federal judge to overturn its 2023 settlement...

Witkoff Backs Tether CEO’s ‘Trillions of Agents’ Crypto Future

World Liberty Financial is expanding rapidly into stablecoins and tokenized assets, positioning USD-backed stablecoins...

Strategy’s Saylor reverses stance, may sell Bitcoin for dividends

Michael Saylor's company, Strategy (formerly MicroStrategy), announced on its Q1 2026 earnings call that...

Must Read

10 BEST Companies to Buy Hosting With Bitcoin And Crypto

If you are looking to buy hosting with bitcoin or cryptocurrency then you've come to the right place.I've done the research for you...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading