The MacSync Stealer malware has recently upgraded its delivery method, removing the need for user interaction and employing more sophisticated stealth techniques. This malware, a rebranded version of Mac.c, now uses signed and notarized applications to evade detection and infect macOS devices more effectively. #MacSyncStealer #macOSMalware
Keypoints
- MacSync Stealer is a rebrand of the earlier Mac.c macOS infostealer introduced in April 2025.
- The malware has expanded its capabilities to include backdoor functions via a Go-based agent.
- The infection chain now uses signed, notarized Swift applications to distribute the malware more stealthily.
- The new distribution method eliminates user interaction by retrieving encoded scripts directly from remote servers.
- Cybersecurity experts observe this trend as an attempt by attackers to make malware appear as legitimate applications.
Read More: https://www.securityweek.com/macsync-macos-malware-distributed-via-signed-swift-application/