New MacSync malware dropper evades macOS Gatekeeper checks

A digitally signed, notarized Swift application is used to provide the most recent version of the MacSync information stealer, which targets macOS systems.

The distribution mechanism, according to security researchers at Apple device management platform Jamf, is a major improvement over earlier versions that employed less advanced “drag-to-Terminal” or ClickFix strategies.

It eliminates the need for direct terminal contact, according to a paper released today by the researchers. It is delivered as a code-signed and notarized Swift application within a disk image called zk-call-messenger-installer-3.9.2-lts.dmg, distributed via https://zkcall.net/download.

According to Jamf, the most recent version of MacSync had a legitimate signature at the time of the investigation and was able to evade inspections by macOS’s security mechanism, Gatekeeper.

We verified that the Mach-O binary, a universal build, is notarized and code-signed after examining it read more about New MacSync malware dropper evades macOS Gatekeeper checks.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *