HomeSecurityMacSync Stealer Bypasses Apple's Malware Protections

MacSync Stealer bypasses Apple's malware protections

We recently saw how ChatGPT was used to trick Mac users into installing MacStealer. Now, a different tactic has been found to convince users to install a new version of MacSync Stealer.

Macs remain a relatively difficult target for attackers. However, Mac malware is on the rise, and two recently discovered tactics highlight the creative approaches some attackers are taking.

Hackers Target Mac Users (Despite Protection Measures)

There were two main reasons that malware for Macs was relatively rare compared to that for Windows machines. The first was the relatively low market share of Macs. The second was the built-in protections that Apple includes to detect and block malicious applications.

See also: Ukrainian confessed to his involvement in Nefilim ransomware

MacSync Stealer

When you try to install a new Mac app, macOS checks to see if it has been validated by Apple as being signed by a known developer. If it hasn't, it will flag that fact and macOS will make the process of bypassing the protection a bit complicated.

Earlier this month, attackers attempted to use ChatGPT and other AI chatbots to trick Mac users into pasting a command line into Terminal, which then installed malware.

Infection with a new version of MacSync Stealer

Cybersecurity firm Jamf, however, has now found an example of another approach being used. Jamf says the malware is a variant of the “increasingly active” MacSync Stealer.

MacSync Stealer bypasses Apple's malware protections

The attackers use a Swift that is signed and validated and does not contain malware itself. However, the application retrieves a coded script from a remote server, which is then executed to install the malware.

“After inspecting the Mach-O binary, which is a global build, it was confirmed that it is both signed and validated. The signature is associated with the Developer Team ID GNJLS3UYZ4.

We also verified the code directory hashes against Apple's recall list and, at the time of analysis, none had been recalled […]

"Most payloads associated with MacSync Stealer tend to run primarily in memory and leave little to no traces on disk," the company says.

See also: Wonderland: Android malware combines dropper, SMS theft and RAT capabilities

MacSync Stealer bypasses Apple's malware protections

This change in distribution reflects a broader trend in the macOS malware landscape, where attackers are increasingly trying to malware their that are signed and validated (to make them look more like legitimate applications). By leveraging these techniques, adversaries are reducing their chances of early detection.

Jamf reported the developer ID to Apple, and the company has now revoked the certificate.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: RansomHouse RaaS: New dangerous capabilities

As always, the best protection against malware for Mac is to install apps from the Mac App Store and websites you trust.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS