MacSync macOS Malware Distributed via Signed Swift Application

MacSync macOS Malware Distributed via Signed Swift Application

The MacSync Stealer malware has recently upgraded its delivery method, removing the need for user interaction and employing more sophisticated stealth techniques. This malware, a rebranded version of Mac.c, now uses signed and notarized applications to evade detection and infect macOS devices more effectively. #MacSyncStealer #macOSMalware

Keypoints

  • MacSync Stealer is a rebrand of the earlier Mac.c macOS infostealer introduced in April 2025.
  • The malware has expanded its capabilities to include backdoor functions via a Go-based agent.
  • The infection chain now uses signed, notarized Swift applications to distribute the malware more stealthily.
  • The new distribution method eliminates user interaction by retrieving encoded scripts directly from remote servers.
  • Cybersecurity experts observe this trend as an attempt by attackers to make malware appear as legitimate applications.

Read More: https://www.securityweek.com/macsync-macos-malware-distributed-via-signed-swift-application/