Mac Fix-it Curitiba

Mac Fix-it Curitiba Soluções e melhorias para Macs incluindo todo tipo de reparo e upgrade. Experiência de mais de 15 anos com o universo Apple. CNPJ: 36.448.783/0001-18

Atendimento mediante agendamento apenas. Troca de HD, instalação de SSD, upgrade de memória, upgrade de processador, upgrade de placa de vídeo, troca de placa lógica, troca de display, troca de vidro de display, troca de chassis e cases, troca de teclado, troca de touchpad, backup, restauração e downgrade de sistema. Soluções de TI e consultoria para Macs.

27/12/2025

Apple's security team reviewed this app. Approved it. But now it steals your passwords, crypto wallets, and Telegram account. 😳 Hundreds of Macs infected since mid-2025.

MacSync Stealer just hit number 6 on Red Canary's top 10 threat list for December 2025. Most victims in Ukraine, the US, Germany, and the UK.

In April 2025, a hacker called "mentalpositive" built a cheap macOS stealer named Mac.c. Price tag: $1,000. That's budget pricing in the malware world. AMOS, the market leader, charges $3,000 per month.

By July, the project was dying. No funding. No future.

Then someone bought it. Rebranded it to MacSync. Added a Go-based backdoor for remote control. And in December, they figured out how to get Apple to approve it.

The trick is simple but effective. The app itself contains no malware. It's a clean Swift application. Apple's automated security scan sees nothing wrong. Signs it. Notarizes it. Approves it for distribution.

After installation, the app silently downloads the actual malware from gatemaden.space. Executes it. Then deletes its tracks.

The dropper includes anti-analysis tricks: it won't run twice within an hour, making automated sandbox detection harder.

What MacSync steals:
→ Your entire iCloud Keychain
→ Browser passwords from Chrome, Safari, Firefox, Brave
→ Crypto wallets: Exodus, Ledger Live, MetaMask, Coinomi
→ Your complete Telegram account
→ Credit card autofill data

But unlike older stealers, MacSync doesn't just grab and go. The Go-based backdoor gives attackers persistent remote access. They can execute commands on your Mac whenever they want. The stolen data gets compressed into a file called /tmp/salmonela.zip (yes, really) and sent to their command server.

Security researcher g0njxa interviewed the criminals behind MacSync. When asked if they target CIS countries like Russia, Ukraine, or Belarus, the answer was clear:

"No. That's a principled position and it will not change."

Make of that what you will. I don't like attribution and will not play that game.

The distribution method is clever. The malware hides inside a fake messenger app called "zk-call" from zkcall.net. The installer is 25MB, stuffed with decoy PDF files to look legitimate and confuse automated scanners.

Apple revoked the developer certificate (Team ID GNJLS3UYZ4) after Jamf Threat Labs reported it.

They'll be back with a new certificate.

How to protect yourself:
→ Only download apps from the Mac App Store or verified developer websites
→ Check the publisher, not just if the app is signed
→ Be suspicious of messenger or crypto apps from unknown sources
→ If an app asks for your password immediately after installation: stop
→ Check Telegram for unknown active sessions (Settings → Devices)

Want to understand how attackers exploit human trust?
My ethical hacking course covers social engineering, phishing, and real attack scenarios.
https://www.udemy.com/course/ethical-hacking-complete-course-zero-to-expert/?couponCode=FEBRUARY26
(The link supports me directly as your instructor!)

Hacking is not a hobby but a way of life.



Research & writing: Jolanda de Koff | HackingPassion.com
Sharing is fine. Copying without credit is not.

24/10/2025

A iFixit publicou hoje o seu vídeo de desmonte do novíssimo MacBook Pro de 14 polegadas, que recentemente foi atualizado com o chip M5, além de ter

25/09/2025

Após o anúncio do macOS Tahoe 26, na WWDC25, a Apple indicou que a próxima grande versão principal do sistema de Macs — ou seja, o macOS 27 — não

11/07/2025

A rumor says Apple won’t get the next-generation MacBook Pro with the upcoming M5 processor out this autumn, as had been expected.

09/07/2025

The hackers behind the infamous Atomic Stealer have added a new component to the malware that allows it to maintain persistence on infected Macs 🚨

Link in the comments for the full story ⬇️

08/07/2025

The Atomic macOS Stealer malware has a new backdoor persistent installation feature, making it even more of a security risk for Mac users.

03/07/2025

AppleInsider today shared a list of alleged identifiers for future Mac models, which should roll out over the next year or so. The report does not...

A2179 com curto no circuito de carga.
15/05/2025

A2179 com curto no circuito de carga.

02/01/2025

Hello 2025…and goodbye 2024! It’s been an exciting first year hosting the Security Bite column on 9to5Mac. I had the...

10/12/2024

9to5Mac Security Bite is exclusively brought to you by Mosyle, the only Apple Unified Platform. Making Apple devices work-ready and enterprise-safe...

Endereço

Rua Pedro Racoski, 444
Curitiba, PR
82110050

Horário de Funcionamento

Segunda-feira 10:00 - 19:00
Terça-feira 10:00 - 19:00
Quarta-feira 10:00 - 19:00
Quinta-feira 10:00 - 19:00
Sexta-feira 10:00 - 19:00

Notificações

Seja o primeiro recebendo as novidades e nos deixe lhe enviar um e-mail quando Mac Fix-it Curitiba posta notícias e promoções. Seu endereço de e-mail não será usado com qualquer outro objetivo, e pode cancelar a inscrição em qualquer momento.

Entre Em Contato Com O Negócio

Envie uma mensagem para Mac Fix-it Curitiba:

Compartilhar