New MacSync Malware Variant Bypasses macOS Security, Targets Crypto Wallets
Security researchers at Jamf Threat Labs and SlowMist have identified a dangerous new variant of the MacSync malware capable of bypassing macOS Gatekeeper protections. The signed and notarized stealer employs sophisticated evasion techniques, including file inflation and self-destruct scripts, while targeting sensitive cryptocurrency wallet data alongside iCloud keychains and browser passwords.
First emerging in April 2025 as 'Mac.C' before rebranding, MacSync has gained traction among cybercriminal groups. SlowMist's CISO confirms the malware has already compromised numerous users, highlighting the growing sophistication of macOS-targeted threats in the crypto space.
The discovery underscores critical security considerations for digital asset holders: download exclusively from trusted sources like the Mac App Store, maintain rigorous system updates, and deploy reputable endpoint protection solutions. As malware increasingly targets crypto wallets, proactive defense measures become paramount for safeguarding digital wealth.