• bitcoinBitcoin (BTC) $ 87,584.00
  • ethereumEthereum (ETH) $ 2,962.69
  • tetherTether (USDT) $ 0.999514
  • bnbBNB (BNB) $ 843.54
  • xrpXRP (XRP) $ 1.87
  • usd-coinUSDC (USDC) $ 0.999704
  • solanaSolana (SOL) $ 123.03
  • tronTRON (TRX) $ 0.284120
  • staked-etherLido Staked Ether (STETH) $ 2,961.97
  • dogecoinDogecoin (DOGE) $ 0.129698
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.03
  • cardanoCardano (ADA) $ 0.361792
  • whitebitWhiteBIT Coin (WBT) $ 56.75
  • bitcoin-cashBitcoin Cash (BCH) $ 576.25
  • wrapped-stethWrapped stETH (WSTETH) $ 3,621.77
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 87,369.00
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 3,219.05
  • usdsUSDS (USDS) $ 0.999583
  • wrapped-eethWrapped eETH (WEETH) $ 3,208.42
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.999290
  • chainlinkChainlink (LINK) $ 12.37
  • moneroMonero (XMR) $ 445.29
  • wethWETH (WETH) $ 2,963.40
  • leo-tokenLEO Token (LEO) $ 8.07
  • stellarStellar (XLM) $ 0.217852
  • zcashZcash (ZEC) $ 417.07
  • ethena-usdeEthena USDe (USDE) $ 0.998849
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 87,525.00
  • litecoinLitecoin (LTC) $ 77.08
  • hyperliquidHyperliquid (HYPE) $ 24.16
  • suiSui (SUI) $ 1.43
  • avalanche-2Avalanche (AVAX) $ 12.15
  • hedera-hashgraphHedera (HBAR) $ 0.110643
  • susdssUSDS (SUSDS) $ 1.08
  • daiDai (DAI) $ 0.999424
  • shiba-inuShiba Inu (SHIB) $ 0.000007
  • usdt0USDT0 (USDT0) $ 0.999182
  • paypal-usdPayPal USD (PYUSD) $ 0.999877
  • uniswapUniswap (UNI) $ 5.85
  • crypto-com-chainCronos (CRO) $ 0.094610
  • the-open-networkToncoin (TON) $ 1.47
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.131293
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.21
  • mantleMantle (MNT) $ 1.05
  • canton-networkCanton (CC) $ 0.090423
  • polkadotPolkadot (DOT) $ 1.76
  • usd1-wlfiUSD1 (USD1) $ 0.999000
  • rainRain (RAIN) $ 0.007981
  • bitget-tokenBitget Token (BGB) $ 3.46
  • tether-goldTether Gold (XAUT) $ 4,531.12
  • memecoreMemeCore (M) $ 1.35
  • okbOKB (OKB) $ 109.68
  • aaveAave (AAVE) $ 150.66
  • falcon-financeFalcon USD (USDF) $ 0.998361
  • bittensorBittensor (TAO) $ 211.69
  • nearNEAR Protocol (NEAR) $ 1.48
  • ethereum-classicEthereum Classic (ETC) $ 12.04
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,963.62
  • hash-2Provenance Blockchain (HASH) $ 0.033467
  • jito-staked-solJito Staked SOL (JITOSOL) $ 153.74
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • pi-networkPi Network (PI) $ 0.205929
  • pepePepe (PEPE) $ 0.000004
  • internet-computerInternet Computer (ICP) $ 3.01
  • aster-2Aster (ASTER) $ 0.687816
  • pax-goldPAX Gold (PAXG) $ 4,537.55
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.14
  • hashnote-usycCircle USYC (USYC) $ 1.11
  • htx-daoHTX DAO (HTX) $ 0.000002
  • ethenaEthena (ENA) $ 0.199147
  • global-dollarGlobal Dollar (USDG) $ 0.999594
  • skySky (SKY) $ 0.065264
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.49
  • kucoin-sharesKuCoin (KCS) $ 10.86
  • ripple-usdRipple USD (RLUSD) $ 0.999716
  • bfusdBFUSD (BFUSD) $ 0.999199
  • midnight-3Midnight (NIGHT) $ 0.078397
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999749
  • worldcoin-wldWorldcoin (WLD) $ 0.488227
  • rocket-pool-ethRocket Pool ETH (RETH) $ 3,415.15
  • ondo-financeOndo (ONDO) $ 0.386038
  • kaspaKaspa (KAS) $ 0.045129
  • aptosAptos (APT) $ 1.60
  • gatechain-tokenGate (GT) $ 10.20
  • binance-staked-solBinance Staked SOL (BNSOL) $ 134.15
  • wbnbWrapped BNB (WBNB) $ 843.60
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.106650
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 3,141.26
  • arbitrumArbitrum (ARB) $ 0.189691
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.02
  • algorandAlgorand (ALGO) $ 0.114017
  • pump-funPump.fun (PUMP) $ 0.001702
  • official-trumpOfficial Trump (TRUMP) $ 4.93
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 87,479.00
  • ignition-fbtcFunction FBTC (FBTC) $ 86,811.00
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 87,303.00
  • cosmosCosmos Hub (ATOM) $ 1.97
  • filecoinFilecoin (FIL) $ 1.30
  • nexoNEXO (NEXO) $ 0.931594
  • flare-networksFlare (FLR) $ 0.011274
  • vechainVeChain (VET) $ 0.010491
  • xdce-crowd-saleXDC Network (XDC) $ 0.048240
  • usddUSDD (USDD) $ 0.999392
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 3,172.27
  • usdtbUSDtb (USDTB) $ 1.00
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 10.93
  • ousgOUSG (OUSG) $ 113.73
  • wrappedm-by-m0WrappedM by M^0 (WM) $ 0.999631
  • beldexBeldex (BDX) $ 0.097419
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999702
  • sei-networkSei (SEI) $ 0.109742
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 87,440.00
  • clbtcclBTC (CLBTC) $ 89,447.00
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.11
  • mantle-staked-etherMantle Staked Ether (METH) $ 3,208.49
  • render-tokenRender (RENDER) $ 1.28
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 3,160.83
  • bonkBonk (BONK) $ 0.000008
  • usdaiUSDai (USDAI) $ 0.999694
  • wrapped-flareWrapped Flare (WFLR) $ 0.011273
  • morphoMorpho (MORPHO) $ 1.18
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999873
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,962.55
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 24.31
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.80
  • myx-financeMYX Finance (MYX) $ 3.14
  • jupiter-exchange-solanaJupiter (JUP) $ 0.189781
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 3,117.63
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 142.50
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.008722
  • usual-usdUsual USD (USD0) $ 0.995389
  • curve-dao-tokenCurve DAO (CRV) $ 0.371493
  • c8ntinuumc8ntinuum (CTM) $ 0.122301
  • tbtctBTC (TBTC) $ 87,264.00
  • optimismOptimism (OP) $ 0.269354
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 2,962.83
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.999267
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.23
  • story-2Story (IP) $ 1.47
  • ghoGHO (GHO) $ 0.999139
  • true-usdTrueUSD (TUSD) $ 0.998447
  • cgeth-hashkey-cloudcgETH Hashkey Cloud (CGETH.HASH) $ 2,460.42
  • fasttokenFasttoken (FTN) $ 1.12
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.209344
  • lido-daoLido DAO (LDO) $ 0.534539
  • dashDash (DASH) $ 37.97
  • gtethGTETH (GTETH) $ 2,966.99
  • tezosTezos (XTZ) $ 0.440708
  • pippinpippin (PIPPIN) $ 0.467554
  • merlin-chainMerlin Chain (MERL) $ 0.427975
  • injective-protocolInjective (INJ) $ 4.58
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.697631
  • ether-fiEther.fi (ETHFI) $ 0.692082
  • blockstackStacks (STX) $ 0.243237
  • spx6900SPX6900 (SPX) $ 0.471114
  • stader-ethxStader ETHx (ETHX) $ 3,192.33
  • aerodrome-financeAerodrome Finance (AERO) $ 0.482657
  • newton-projectAB (AB) $ 0.004700
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 3,184.28
  • msolMarinade Staked SOL (MSOL) $ 165.78
  • usdbUSDB (USDB) $ 0.993174
  • swethSwell Ethereum (SWETH) $ 3,276.23
  • wrapped-apecoinWrapped ApeCoin (WAPE) $ 0.197509
  • starknetStarknet (STRK) $ 0.079662
  • justJUST (JST) $ 0.039836
  • sbtc-2sBTC (SBTC) $ 87,737.00
  • the-graphThe Graph (GRT) $ 0.036405
  • sun-tokenSun Token (SUN) $ 0.020121
  • flokiFLOKI (FLOKI) $ 0.000040
  • celestiaCelestia (TIA) $ 0.445724
  • bittorrentBitTorrent (BTT) $ 0.00000039
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 3,311.44
  • doublezeroDoubleZero (2Z) $ 0.108085
  • bitcoin-svBitcoin SV (BSV) $ 18.73
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.11
  • apenftAINFT (NFT) $ 0.00000037
  • syrupMaple Finance (SYRUP) $ 0.315591
  • telcoinTelcoin (TEL) $ 0.003814
  • olympusOlympus (OHM) $ 22.07
  • ethereum-name-serviceEthereum Name Service (ENS) $ 9.44
  • conflux-tokenConflux (CFX) $ 0.069805
  • euro-coinEURC (EURC) $ 1.18
  • chilizChiliz (CHZ) $ 0.035132
  • iotaIOTA (IOTA) $ 0.084178
  • cap-usdCap USD (CUSD) $ 1.00
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 87,549.00
  • kinesis-goldKinesis Gold (KAU) $ 145.24
  • trust-wallet-tokenTrust Wallet (TWT) $ 0.827533
  • kaiaKaia (KAIA) $ 0.058560
  • pyth-networkPyth Network (PYTH) $ 0.058087
  • resolv-usrResolv USR (USR) $ 0.999407
  • crvusdcrvUSD (CRVUSD) $ 0.999551
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.129665
  • usxUSX (USX) $ 0.998933
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.12
  • gnosisGnosis (GNO) $ 122.14
  • dogwifcoindogwifhat (WIF) $ 0.318878
  • binance-peg-busdBinance-Peg BUSD (BUSD) $ 0.999649
  • jasmycoinJasmyCoin (JASMY) $ 0.006309

New MacSync malware variant bypasses macOS security, Jamf and SlowMist warn

0 1

New MacSync malware variant bypasses macOS security, Jamf and SlowMist warn

While reviewing the detections of its in-house YARA rules, Jamf Threat Labs claims it observed a signed and notarized stealer that did not follow the typical execution chains seen in the past.

According to 23pds from Slowmist, this stealer is a new variant of the MacSync variant famous for bypassing macOS security.

Slowmist claims user info already stolen

In an X post, Slowmist’s Chief Information Security Officer, 23pds claimed that there is a new variant of the MacSync that bypasses the macOS gatekeeper security system, and it has already hijacked the information of many users.

According to 23pds, to evade detection, the variant employs techniques like file inflation, network connection verification and self-destruct scripts after execution. It can reportedly steal sensitive data like iCloud keychains, browser passwords, and crypto wallets.

The warning came attached to a blog from Jamf Threat Labs, reporting that this is not its first contact with MacSync.

The macOS-targeted information stealer malware reportedly first emerged in April 2025 as “Mac.C”, developed by a threat actor known as “Mentalpositive”. It was rebranded to MacSync shortly after, which it quickly gained traction among cybercriminals.

To protect yourself from it, only download apps from the Mac App Store or trusted developer websites, keep your macOS and apps updated, use reputable antivirus/endpoint security tools that detect macOS threats, and be cautious with unexpected .dmg files or installers, especially those promising crypto-related or messaging tools.

Is there a new MacSync malware?

The sample in question reportedly looked highly similar to past variants of the increasingly active MacSync Stealer malware but was revamped in its design. It differed from earlier MacSync Stealer variants that primarily rely on drag-to-terminal or ClickFix-style techniques, as it employs a more deceptive, hands-off approach.

The sample is reportedly delivered as a code-signed and notarized Swift application within a disk image named zk-call-messenger-installer-3.9.2-lts.dmg, distributed via https://zkcall.net/download.

That removes the need for any direct terminal interaction. Instead, the dropper retrieves an encoded script from a remote server and executes it via a Swift-built helper executable

Jamf Threat Labs also observed the Odyssey infostealer adopting similar distribution methods in recent variants. They expressed surprise that the familiar right-click open instruction is still present in the new sample, even though the executable is signed and does not require this step.

“After inspecting the Mach-O binary, which is a universal build, we confirmed that it is both code-signed and notarized. The signature is associated with the Developer Team ID GNJLS3UYZ4,” they claimed.

They made sure to verify the code directory hashes against Apple’s revocation list, and at the time of analysis, said none had been revoked.

Another notable observation made is the unusually large size of the disk image (25.5MB), which they said appears to be inflated by decoy files embedded within the app bundle.

At the time of analysis, some of the samples uploaded to VirusTotal were detected by only one antivirus engine, while others were flagged by up to thirteen. After confirming that the Developer Team ID was used to distribute malicious payloads, Jamf Threat Labs reported it to Apple. Since then, the associated certificate has been revoked.

The smartest crypto minds already read our newsletter. Want in? Join them.

Source

Leave A Reply

Your email address will not be published.