MacSync Stealer Targets Crypto Wallets via Notarized Swift Apps on macOS

MacSync Stealer has significantly advanced on macOS with user assets already stolen, 23pds said on Dec. 23, BlockBeats reports. The new build no longer requires Terminal steps and is distributed as zk-call-messenger-installer-3.9.2-lts.dmg, a code-signed, Apple-notarized Swift app under developer team ID GNJLS3UYZ4, with hashes not revoked at analysis time. A Swift helper fetches and executes encoded scripts from a remote server, while the unusually large DMG contains LibreOffice-related PDFs as decoys. The malware targets browser data, account credentials and crypto wallet information.