PULSE NAME
MacSync Stealer Evolves: From ClickFix to Code-Signed Swift Malware
WHITE MacSync Stealer AlienVault 2025-12-23 Modified: 2025-12-23
14
IOCs
MEDIUM VOLUME
MacSync Stealer malware has evolved from using drag-to-terminal and ClickFix techniques to a more sophisticated approach. The new variant is delivered as a code-signed and notarized Swift application within a disk image, eliminating the need for direct terminal interaction. The malware retrieves an encoded script from a remote server and executes it via a Swift-built helper executable. The installer is signed with Developer Team ID GNJLS3UYZ4 and contains decoy files to inflate its size. The malware performs various checks, including internet connectivity and execution timing, before downloading and executing the second-stage payload. This evolution reflects a broader trend in macOS malware, where attackers attempt to bypass security measures by using signed and notarized executables.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
MacSync Stealer Odyssey infostealer
Indicators of Compromise (10 / 14 total)
All FileHash-SHA256 URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 06c74829d8eee3c47e17d01c41361d314f12277d899cc9dfa789fe767c03693e 2025-12-23
FileHash-SHA256 2e671bd9673d174de9b4ad8fd03049859e1d2d17ac9bc49ecc5d736505002937 2025-12-23
FileHash-SHA256 4ae745bc0e4631f676b3d0a05d5c74e37bdfc8da3076208b24e73e5bbea9178f 2025-12-23
FileHash-SHA256 7cfe0b119e616ac81ddb1767a5c7f40bec67d91fdd66e53490c0225789537073 2025-12-23
FileHash-SHA256 985683bd660c0c47c6be513a2d1f0a554d52d241714bb17fb18ab0d0f8cc2dc6 2025-12-23
FileHash-SHA256 9990457feac0cd85f450e60c268ddf5789ed4ac81022b0d7c3021d7208ebccd3 2025-12-23
FileHash-SHA256 9d43e059111460c4f81351a062fb7eb7dbfd34988a06d756c7206f330c06cb42 2025-12-23
FileHash-SHA256 be961ec5b9f4cc501ed5d5b8974b730dabcdf7e279ed4a8c037c67b5b935d51a 2025-12-23
FileHash-SHA256 c4d3e5cdb264eded917cd61b8131c40715c0ee3f4d2c94c84d60fa295ca4ed97 2025-12-23
FileHash-SHA256 ecfaa20f25e11878686249c7094706bc3dcd2dc0ace0f2932a39d1bfdac85863 2025-12-23