MacSync Stealer: Apple-Notarized Malware Bypasses Gatekeeper - Complete Security Guide 2025
Comprehensive security analysis of MacSync Stealer malware that bypasses macOS Gatekeeper through Apple's notarization process. Learn detection methods, removal steps, and protection strategies against this sophisticated macOS threat.
A sophisticated new variant of MacSync Stealer malware has emerged that exploits Apple's own security infrastructure to bypass Gatekeeper protections. Discovered by Jamf Threat Labs in December 2025, this threat represents a significant evolution in macOS malware distribution, using code-signed and Apple-notarized applications to evade detection and steal sensitive data including cryptocurrency wallets, browser credentials, and system information.

Executive Summary: The MacSync Stealer Threat
Critical Security Alert
MacSync Stealer represents one of the most sophisticated macOS malware threats of 2025, exploiting a fundamental weakness in Apple's security architecture. Unlike previous malware that relied on tricking users into bypassing security warnings, this variant passes all Gatekeeper and XProtect checks because it carries legitimate Apple notarization.
Key Threat Characteristics:
- Apple-Notarized: Passes Gatekeeper security checks without warnings
- Code-Signed: Uses valid Developer ID (Team ID: GNJLS3UYZ4, now revoked)
- Multi-Stage Payload: Initial binary is benign; malicious payload delivered post-installation
- Comprehensive Data Theft: Targets browsers, cryptocurrency wallets, Keychain, and Telegram
- Backdoor Capability: Includes Go-based backdoor for persistent access
Who Is at Risk:
- Cryptocurrency holders and traders
- Users who download software from unofficial sources
- Enterprise environments without advanced endpoint protection
- Anyone who trusts applications solely based on Gatekeeper approval
The Growing macOS Malware Landscape
The MacSync Stealer emergence occurs against a backdrop of rapidly escalating macOS threats:
| Metric | 2024 vs 2025 |
|---|---|
| macOS Threat Growth | 400% increase (Red Canary) |
| AMOS Malware Detections | 300% spike in August 2025 |
| ClickFix Attack Surge | 517% increase in H1 2025 |
| Mac Users Encountering Threats | 66% experienced at least one cyber threat |
| Global AMOS Campaign Reach | 120+ countries |
The entry-level price for Mac stealer malware has dropped from $3,000 to $1,000 per month, making these tools accessible to a broader range of cybercriminals.
Technical Analysis: How MacSync Stealer Works
Origins and Evolution
MacSync Stealer emerged as a rebrand of the "mac.c stealer," which first appeared in April 2025 under the threat actor "Mentalpositive." The malware was subsequently acquired and significantly enhanced by a developer who transformed it from a basic credential stealer into a comprehensive threat with backdoor capabilities.
Technical Architecture:
- Primary Component: C-based data-stealing module
- Persistence Mechanism: Fully-featured Go-based backdoor agent
- Distribution Model: Malware-as-a-Service (MaaS)
- Current Market Price: $1,000/month (down from $3,000)
The Notarization Bypass Technique
The December 2025 variant represents a paradigm shift in macOS malware distribution. Rather than relying on social engineering to bypass security warnings, attackers exploit Apple's own security infrastructure.
Attack Flow:
1. Attacker creates benign Swift application
↓
2. Submits to Apple for notarization
↓
3. Apple's automated scanning approves (no malware detected)
↓
4. Attacker receives notarization ticket
↓
5. Application distributed with valid signature
↓
6. User downloads and opens without Gatekeeper warning
↓
7. Post-installation, app contacts C2 server
↓
8. Malicious payload delivered and executed
↓
9. Data exfiltration begins
Why This Attack Succeeds:
Apple's notarization process evaluates what exists at submission time, not runtime behavior. Security researcher Jeff Johnson (Lapcat Software) explains: "Apple's notarization service scans for malware, but malware authors don't need to submit malware to Apple! They can submit a perfectly innocent app for notarization... It's impossible for Apple to detect this beforehand."
Detailed Infection Chain
Stage 1: Initial Distribution
The malware distributes as a disk image named zk-call-messenger-installer-3.9.2-lts.dmg, hosted at https://zkcall.net/download. The DMG file is inflated to 25.5MB using decoy PDF files (LibreOffice-related documents) to appear legitimate.
Stage 2: Pre-Execution Validation
Upon mounting, the code-signed Swift executable performs several checks:
// Simplified representation of pre-execution checks
func checkInternet() -> Bool {
// Verify network connectivity
// Avoids execution in sandboxed/offline environments
}
func checkRateLimit() -> Bool {
// Enforce 3600-second minimum between executions
// Prevents analysis through repeated runs
}
Stage 3: Payload Retrieval
If checks pass, the application:
- Fetches obfuscated bash script from
gatemaden.space - Writes script to
/tmp/runnerwith executable permissions - Validates script authenticity via file-type inspection
- Expects: "Paul Falstad's zsh script text executable"
Stage 4: Payload Execution
# Decoded payload execution
base64 -D | gunzip | /bin/zsh -lc
# Evaluates daemon_function() routine
Stage 5: Data Exfiltration
The malware communicates with focusgroovy.com for credential theft operations:
- Displays fake password prompt to harvest system credentials
- Deploys Go-based backdoor for persistent access
- Exfiltrates collected data to command and control infrastructure
Evasion Techniques
MacSync Stealer employs multiple sophisticated evasion mechanisms:
| Technique | Purpose |
|---|---|
| DMG inflation with decoy files | Appear legitimate, bypass file-size heuristics |
| In-memory execution | Minimize disk artifacts for forensic analysis |
| Internet connectivity checks | Avoid sandboxed analysis environments |
| Quarantine attribute removal | Bypass macOS security flags |
Script validation via /usr/bin/file | Ensure payload integrity |
Modified curl flags (-fL, -sS, --noproxy) | Evade network monitoring |
| Rate limiting (3600s intervals) | Prevent automated analysis |
What Data MacSync Stealer Targets
Browser Credentials and Data
MacSync Stealer targets every major Chromium-based browser:
Targeted Browsers:
- Google Chrome (including Beta, Dev, Canary)
- Brave Browser
- Microsoft Edge
- Vivaldi
- Opera / Opera GX
- Yandex Browser
- Arc Browser
- Chromium
Data Extracted:
- Saved passwords and login credentials
- Browser cookies (session tokens for account takeover)
- Form autofill data (addresses, credit cards)
- Browsing history
- Extension secrets and configurations
Cryptocurrency Wallets
The malware specifically targets cryptocurrency assets, reflecting the high-value nature of this data:
Standalone Wallet Applications:
- Exodus
- Electrum
- Atomic Wallet
- Guarda
- Coinomi
- Sparrow
- Wasabi
- Bitcoin Core
- Litecoin Core
- Dash Core
- Dogecoin Core
- BlueWallet
- Zengo
- Trust Wallet
- Ledger Live
- Trezor Suite
Browser-Based Wallets:
- MetaMask
- Coinbase Wallet
- Phantom
- Other browser extension wallets
System and Application Data
Keychain Access:
- iCloud Keychain credentials
- Wi-Fi passwords
- Application passwords
- Stored certificates
Communication Apps:
- Telegram session data (enables full account takeover)
- Messaging app credentials
System Information:
- Hardware specifications
- Installed applications list
- Network configurations
- macOS version and system metadata
Personal Files:
- Documents and images
- Corporate/business data
- Configuration files
Indicators of Compromise (IOCs)
File Hashes (SHA256)
Disk Images:
zk-call-messenger-installer-3.9.2-lts.dmg:
be961ec5b9f4cc501ed5d5b8974b730dabcdf7e279ed4a8c037c67b5b935d51a
co.runtime.helper.b3f9a2.dmg:
4ae745bc0e4631f676b3d0a05d5c74e37bdfc8da3076208b24e73e5bbea9178f
Mach-O Executables (runtimectl):
ecfaa20f25e11878686249c7094706bc3dcd2dc0ace0f2932a39d1bfdac85863
7cfe0b119e616ac81ddb1767a5c7f40bec67d91fdd66e53490c0225789537073
06c74829d8eee3c47e17d01c41361d314f12277d899cc9dfa789fe767c03693e
c4d3e5cdb264eded917cd61b8131c40715c0ee3f4d2c94c84d60fa295ca4ed97
9990457feac0cd85f450e60c268ddf5789ed4ac81022b0d7c3021d7208ebccd3
9d43e059111460c4f81351a062fb7eb7dbfd34988a06d756c7206f330c06cb42
Payload Script (runner):
2e671bd9673d174de9b4ad8fd03049859e1d2d17ac9bc49ecc5d736505002937
Network Indicators
| Indicator Type | Value |
|---|---|
| User Agent | UserSyncWorker/1.0 (macOS) |
| C2 Domain | focusgroovy.com |
| Payload Domain | gatemaden.space |
| Distribution Domain | zkcall.net |
| Developer Team ID | GNJLS3UYZ4 (revoked) |
File System Indicators
Temporary Files:
/tmp/runner(temporary payload)/tmp/runner.headers(header cache)
Persistence Locations:
~/Library/Logs/UserSyncWorker.log~/Library/Application Support/UserSyncWorker/
Timing Tracker Files:
last_upgatelast_update
Log Patterns
Look for these patterns in system logs:
- "Starting update..."
- "rate-limit: defer"
- "preflight: internet="
Detection Methods
Using Activity Monitor
- Open Applications > Utilities > Activity Monitor
- Click the CPU tab and sort by %CPU usage
- Look for unfamiliar processes consuming high resources
- Check for processes named similar to "UserSyncWorker"
- Select suspicious processes and click 'i' for more information

Terminal Commands for Detection
Check Network Connections:
# View active network connections
netstat -an | grep ESTABLISHED
# List processes with network connections
lsof -i -P | grep ESTABLISHED
Examine Running Daemons:
# List all running agents and daemons
launchctl list
# Check for suspicious XPC services
launchctl print system
Check Previous Logins:
# View login history for unauthorized access
last
Search for IOC Files:
# Check for MacSync-specific files
ls -la /tmp/runner* 2>/dev/null
ls -la ~/Library/Logs/UserSyncWorker.log 2>/dev/null
ls -la ~/Library/Application\ Support/UserSyncWorker/ 2>/dev/null
Check LaunchAgents:
# List user LaunchAgents
ls -la ~/Library/LaunchAgents/
# List system LaunchAgents
ls -la /Library/LaunchAgents/
# List LaunchDaemons
ls -la /Library/LaunchDaemons/
Antivirus Detection Names
Different security vendors may detect MacSync Stealer under various names:
| Vendor | Detection Name |
|---|---|
| Avast | MacOS:Agent-AYE [PUP] |
| Combo Cleaner | Trojan.GenericKD.77251890 |
| Kaspersky | HEUR:Trojan.OSX.Agent.gen |
Removal Guide
Immediate Response Steps
Step 1: Disconnect from Network
# Disable Wi-Fi from Terminal
networksetup -setairportpower en0 off
Or manually: Click Wi-Fi icon > Turn Wi-Fi Off
Unplug Ethernet cables to prevent further data exfiltration.
Step 2: Boot into Safe Mode
For Apple Silicon Macs:
- Shut down your Mac
- Press and hold the power button until "Loading startup options" appears
- Select your volume
- Press and hold Shift, then click "Continue in Safe Mode"
For Intel Macs:
- Restart your Mac
- Immediately press and hold Shift
- Release when login window appears
Step 3: Remove Suspicious Files
# Remove known MacSync files
rm -rf /tmp/runner
rm -rf /tmp/runner.headers
rm -rf ~/Library/Logs/UserSyncWorker.log
rm -rf ~/Library/Application\ Support/UserSyncWorker/
# Check and remove suspicious LaunchAgents
# First, list them to identify suspicious entries
ls -la ~/Library/LaunchAgents/
ls -la /Library/LaunchAgents/
ls -la /Library/LaunchDaemons/
# Remove any suspicious .plist files (replace with actual filename)
# launchctl unload ~/Library/LaunchAgents/suspicious.plist
# rm ~/Library/LaunchAgents/suspicious.plist
Step 4: Review Login Items
- Open System Settings > General > Login Items
- Review all listed applications
- Remove any unrecognized entries by clicking the minus (-) button
Step 5: Reset Browsers
For Chrome:
- Open Chrome > Settings > Reset settings
- Click "Restore settings to their original defaults"
- Confirm by clicking "Reset settings"
For Safari:
- Safari > Settings > Privacy > Manage Website Data
- Remove All
- Clear History: Safari > Clear History > All History
For Other Browsers: Follow similar reset procedures in each browser's settings.
Step 6: Run Antimalware Scan
Recommended tools:
- Combo Cleaner: Comprehensive Mac malware removal
- Malwarebytes for Mac: Free scanning with paid removal
- Moonlock: Lightweight Mac-native protection
Step 7: Change All Credentials
After removal, immediately:
- Change all passwords stored in browsers or Keychain
- Revoke and regenerate 2FA tokens
- Transfer cryptocurrency to new wallets with new seed phrases
- Monitor accounts for unauthorized activity
Protection Strategies
Software Download Safety
Best Practices:
- Install apps only from the Mac App Store or verified developer websites
- Avoid downloading software from unknown or unofficial sources
- Double-check URLs before downloading (look for typos or suspicious domains)
- Be extremely cautious with "cracked" software or installers found on forums
- Verify application signatures before installation
How to Verify Application Signatures:
- Right-click the app > Select "Get Info"
- Look for Developer ID information under "General" section
- Be wary of applications signed by unknown developers
Enable macOS Security Features
Gatekeeper Settings:
- System Settings > Privacy & Security
- Under "Allow applications downloaded from," select "App Store and identified developers"
- Never disable Gatekeeper permanently
Keep XProtect Updated:
- XProtect updates automatically in the background
- Ensure automatic updates are enabled in System Settings
Enable FileVault:
- System Settings > Privacy & Security > FileVault
- Turn on FileVault for full-disk encryption
- Store recovery key securely
Keep SIP Enabled:
- System Integrity Protection should remain enabled
- Never disable SIP unless absolutely necessary for specific development tasks
Browser Security Best Practices
- Use a Password Manager: Don't rely on browser-stored passwords
- Enable 2FA: Activate two-factor authentication for all critical accounts
- Regular Extension Audits: Review and remove unnecessary browser extensions
- Clear Session Data: Periodically clear cookies and session data
- Use Separate Profiles: Create separate browser profiles for sensitive activities
Cryptocurrency Protection
Hardware Wallet Usage:
- Use hardware wallets (Ledger, Trezor) for significant holdings
- Never enter seed phrases on any website or application
- Verify wallet addresses on the hardware device screen before transactions
Software Wallet Security:
- Enable all available 2FA options on exchange accounts
- Use multi-signature wallets for large amounts
- Store recovery phrases offline in multiple secure locations
- Verify wallet software downloads from official sources only
Transaction Safety:
- Always verify addresses before sending cryptocurrency
- Use a separate device to confirm large transactions
- Be suspicious of any request to "verify" or "validate" your wallet
Enterprise Security Recommendations
Endpoint Protection:
- Deploy EDR solutions like Jamf Protect, CrowdStrike, or SentinelOne
- Enable advanced threat controls in "block mode"
- Implement application whitelisting where possible
MDM Configuration:
- Use Mobile Device Management for centralized security policy
- Restrict software installation to approved sources
- Enable automatic security updates
User Training:
- Conduct regular security awareness training
- Emphasize risks of downloading software from unofficial sources
- Establish clear reporting procedures for suspicious activity
Network Security:
- Implement DNS filtering to block known malicious domains
- Monitor network traffic for suspicious C2 communications
- Segment network to limit lateral movement
Apple's Response and Security Implications
Actions Taken
Following Jamf Threat Labs' disclosure:
- Apple revoked the certificate associated with Developer Team ID GNJLS3UYZ4
- The specific signing certificate is no longer valid for new installations
Important Limitation: Code directory hashes were not included in Apple's revocation list at the time of Jamf's report publication, meaning some variants may still execute on systems that previously allowed them.
The Fundamental Security Challenge
The MacSync case exposes a fundamental weakness in Apple's security architecture:
Design Limitation: Notarization evaluates submissions at a point in time, not runtime behavior. This creates an inherent window of vulnerability.
Expert Analysis:
Security researcher Chris Miller notes that Gatekeeper only verifies developer certificates and checks known-malware lists when an application is first opened. Malware that passes initial inspection won't be stopped later.
The Reality: The system largely works as designed. Code signing and notarization were never intended to guarantee software remains benign forever—only that it can be traced and revoked when abuse is discovered. However, this reactive approach leaves users vulnerable during the detection gap.
What This Means for Users
- Notarization is not a guarantee: A notarized app can still be malicious
- First-run checks are not sufficient: Malware can activate after initial approval
- Vigilance remains essential: Users must maintain security awareness regardless of Gatekeeper approval
- Defense in depth: Multiple security layers are necessary for comprehensive protection
Related macOS Threats
AMOS (Atomic macOS Stealer)
The most prevalent Mac malware in the cybercriminal underground for three years:
- Active since April 2023
- 2025 update added embedded backdoor for persistent access
- Second known case of backdoor deployment at global scale (after North Korean hackers)
- Targets similar data categories as MacSync
Nova Stealer
Emerged November 2025:
- Focuses primarily on cryptocurrency theft
- Masquerades as legitimate wallet software (Ledger Live, Trezor Suite)
- Uses social engineering to gain initial access
Cthulhu Stealer
Another active information stealer with:
- Similar data-stealing capabilities
- Primary focus on browser credentials and cryptocurrency
- Different distribution methods but comparable impact
Recommended Security Solutions
For Individual Users
| Solution | Price | Key Features |
|---|---|---|
| Moonlock | $37.80/year | Lightweight, Mac-native, real-time protection |
| Malwarebytes | Free (basic) / $44.99/year | On-demand scanning, real-time (paid) |
| Intego VirusBarrier | $49.99/year | Comprehensive Mac security suite |
| Combo Cleaner | $59.95/year | Malware removal, system optimization |
For Enterprise
| Solution | Key Features |
|---|---|
| Jamf Protect | Native macOS EDR, MDM integration, threat prevention |
| CrowdStrike Falcon | Cross-platform EDR, threat intelligence |
| Microsoft Defender for Endpoint | Unified security, Azure integration |
| SentinelOne | AI-powered detection, automated response |
| Trellix Endpoint Security | Enterprise-grade protection, policy management |
Conclusion: Staying Safe in an Evolving Threat Landscape
The MacSync Stealer variant discovered in December 2025 represents a significant evolution in macOS malware sophistication. By exploiting Apple's notarization process, attackers have found a way to distribute malware that bypasses the security measures most users rely upon.
Key Takeaways:
-
Trust but Verify: Apple notarization is not a guarantee of safety. Always verify the source and legitimacy of software before installation.
-
Defense in Depth: Rely on multiple security layers—Gatekeeper, XProtect, third-party antimalware, and security best practices.
-
Cryptocurrency Vigilance: If you hold cryptocurrency, use hardware wallets and never expose seed phrases to any software.
-
Stay Updated: Keep macOS, security definitions, and all applications updated to benefit from the latest protections.
-
Report Suspicious Activity: If you encounter suspected malware, report it to Apple and security researchers to help protect the community.
The macOS threat landscape continues to evolve rapidly. While Macs remain generally secure compared to other platforms, the growing sophistication of threats like MacSync Stealer demonstrates that no system is immune. Maintaining awareness, following security best practices, and using appropriate security tools are essential for protecting your data and digital assets.
Frequently Asked Questions
How do I know if my Mac is infected with MacSync Stealer?
Check for these indicators:
- Files in
/tmp/runneror~/Library/Application Support/UserSyncWorker/ - Unusual processes named "UserSyncWorker" in Activity Monitor
- Unexpected network connections to unfamiliar domains
- Missing cryptocurrency or unauthorized account access
Can MacSync Stealer steal my iCloud Keychain passwords?
Yes, MacSync Stealer can access Keychain data if it obtains your system password through its fake password prompt. This is why you should never enter your password into unexpected dialogs.
Does Apple's XProtect protect against MacSync Stealer?
XProtect may detect known variants after Apple updates its definitions. However, new variants can evade detection until signatures are updated. This is why additional security measures are recommended.
Should I stop using Mac because of this malware?
No. While MacSync Stealer is sophisticated, Macs remain secure when users follow best practices. The key is awareness and proper security hygiene—downloading software only from trusted sources, using strong passwords, and maintaining updated security software.
How can I protect my cryptocurrency from Mac malware?
- Use hardware wallets for significant holdings
- Never enter seed phrases into any application or website
- Enable 2FA on all exchange accounts
- Verify all transactions on a separate device
- Consider using a dedicated device for cryptocurrency activities
Is my business at risk from MacSync Stealer?
Yes, especially if employees download software from unofficial sources. Implement MDM solutions, deploy endpoint protection, conduct security awareness training, and establish clear policies for software installation.
Last Updated: December 30, 2025
For additional security resources and macOS protection guides, explore our Security Category or check our comprehensive macOS Tahoe Security & Privacy Guide.
