Lookonchain APP

App Store

macOS Trojan Update: Spreading through Signed App with User Data Encryption Poses Increased Stealth Risk

2025.12.23 14:30:28

On December 23, SlowMist Chief Security Officer 23pds shared a post noting that the **MacSync Stealer** malware—active on macOS—has undergone significant evolution, with user assets already compromised. Early versions relied on "drag-and-drop to terminal" and "ClickFix" tactics to trick users; the latest iteration has upgraded to **code-signed, Apple-notarized Swift applications**, drastically boosting stealth. Researchers identified the sample spreading via a disk image (DMG) named `zk-call-messenger-installer-3.9.2-lts.dmg`, disguised as an instant messaging or utility app to lure downloads. Unlike prior variants, the new version requires no terminal actions from users—instead, a built-in Swift helper fetches and runs code from a remote server to execute information theft. The malware is fully code-signed and notarized by Apple, with developer Team ID `GNJLS3UYZ4`. At the time of analysis, Apple had not revoked its associated hashes, granting it higher "trustworthiness" under macOS’s default security settings and making it easier to bypass user vigilance. The DMG also has an unusually large size, containing bait files like LibreOffice-related PDFs to further reduce suspicion. Security researchers note such info-stealing trojans typically target browser data, account credentials, and cryptocurrency wallet details. As malware increasingly abuses Apple’s signing and notarization systems, macOS-based cryptocurrency users face growing risks of phishing attacks and private key exposure.
Relevant content

Iranian Deputy Foreign Minister: Studying Fee for Ships Passing Through Strait of Hormuz

April 2 (Local Time) — Iranian Deputy Foreign Minister Abadi stated that Iran is considering imposing passage fees on vessels transiting the Strait of Hormuz. He added that the fee standards remain under review and no specific amount has been finalized yet. (CCTV News)

2 minutes ago

Gray Scale: Oil Price Shock and Iran War Risk Keep Crypto Investors Cautiously Optimistic

April 2nd — Per CoinDesk, crypto asset manager Grayscale says Middle East geopolitical tensions have pushed crypto investors into a wait-and-see stance, dimming the previously improving macro backdrop. “The Iran conflict nearly overshadowed all other market dynamics in March,” the report noted. Before tensions escalated, global economic growth had positive momentum and central banks were leaning toward rate cuts. But a sharp rise in oil prices stoked inflation concerns, lifted rate-hike expectations, and pressured risk assets. Since the Middle East conflict flared, the crypto market has seen sharp swings but remained range-bound, with trends closely tied to oil price headline volatility and risk sentiment. Bitcoin dropped to around $60,000 amid initial escalation, then rebounded to near the lower end of $70,000 before pulling back as tensions persisted and macro conditions tightened. The latest round of escalation saw Bitcoin shed roughly 10% from its March peak. Still, Bitcoin h

2 minutes ago

Pumpcade Completes $1 Million Pre-Seed Funding Round, Led by Pump.fun

April 2 — Prediction market platform Pumpcade has closed a $1 million pre-seed funding round, with Pump.fun leading the round and participation from Foundation Capital and angel investor RadioSolace, per The Block. The funds will fuel the development of an arcade gaming experience integrated into Pump.fun’s real-time chat platform.

2 minutes ago

US Stock Market Open Cryptocurrency Concept Stocks Generally Down, GEMI Falls Over 6%

U.S. stocks opened lower on April 2: the Dow Jones Industrial Average (Dow) fell 1.01%, the S&P 500 dropped 0.93%, and the Nasdaq Composite declined 1.40%. Crypto-related stocks were broadly lower, with notable movers including Gemini (GEMI) down 6.78%, Sharplink Gaming (SBET) 6.04% lower, Bitmine (BMNR) off 5.92%, Bit Digital (BTBT) down 5.49%, Circle (CRCL) 5.30% lower, Robinhood (HOOD) off 4.66%, Coinbase (COIN) down 4.61%, and Bullish (BLSH) 4.11% lower.

2 minutes ago

Citigroup: Global Oil Supply Crunch of 440,000 Barrels/Day Expected

Citi said on April 2 that global oil supply could face a shortfall of 440,000 barrels per day (bpd). If some Gulf states reject Iran’s so-called “transit fee,” the shortfall could widen to 800,000 bpd. (Golden Ten)

2 minutes ago

A whale has transferred 450,000 HYPE to HyperCore and started selling.

On April 2, per MLM Monitor, crypto whale "Loracle" transferred 450k HYPE tokens (valued at ~$15.5M) from HyperEVM to HyperCore and began selling them roughly 20 minutes ago.

2 minutes ago