Scan to download
BTC $73,590.17 -2.00%
ETH $2,017.14 -1.94%
BNB $640.60 -1.81%
XRP $1.32 -0.79%
SOL $82.42 -1.29%
TRX $0.3534 -4.32%
DOGE $0.1001 -1.71%
ADA $0.2354 -1.89%
BCH $301.39 -12.15%
LINK $9.02 -3.05%
HYPE $60.67 +0.90%
AAVE $81.38 -4.21%
SUI $0.9317 -5.31%
XLM $0.2083 +24.54%
ZEC $557.13 +1.05%
BTC $73,590.17 -2.00%
ETH $2,017.14 -1.94%
BNB $640.60 -1.81%
XRP $1.32 -0.79%
SOL $82.42 -1.29%
TRX $0.3534 -4.32%
DOGE $0.1001 -1.71%
ADA $0.2354 -1.89%
BCH $301.39 -12.15%
LINK $9.02 -3.05%
HYPE $60.67 +0.90%
AAVE $81.38 -4.21%
SUI $0.9317 -5.31%
XLM $0.2083 +24.54%
ZEC $557.13 +1.05%

disguise

macOS Trojan Upgrade: Disguised as Signed Applications for Distribution, Users Face More Subtle Risks

The Chief Information Security Officer of Slow Fog, 23pds, shared that the MacSync Stealer malware, active on the macOS platform, has shown significant evolution, with user assets already being stolen.The forwarded article mentions that it has upgraded from early low-threshold inducement methods like "dragging to terminal" and "ClickFix" to code signing and notarized Swift applications by Apple, significantly enhancing its concealment. Researchers found that the sample spreads in the form of a disk image named zk-call-messenger-installer-3.9.2-lts.dmg, disguising itself as instant messaging or utility applications to induce users to download. Unlike previous versions, the new version does not require any terminal operations from the user; instead, a built-in Swift helper pulls and executes encoded scripts from a remote server, completing the information theft process.The malware has completed code signing and has been notarized by Apple, with the developer team ID being GNJLS3UYZ4, and the relevant hash has not been revoked by Apple during analysis. This means it has a higher "trustworthiness" under the default macOS security mechanisms, making it easier to bypass user vigilance. The research also found that the DMG is unusually large, containing bait files such as LibreOffice-related PDFs to further reduce suspicion.Security researchers point out that such information-stealing Trojans often target browser data, account credentials, and cryptocurrency wallet information. As malware begins to systematically abuse Apple’s signing and notarization mechanisms, the risks of phishing and private key leakage for cryptocurrency users in the macOS environment are on the rise.

WeChat Security Center: Be vigilant against pyramid schemes and scams disguised as blockchain virtual currencies, stablecoins, and other names

The WeChat Security Center stated that it has recently received user complaints about certain WeChat accounts engaging in illegal activities such as organizing pyramid schemes and fraud within WeChat groups. Such activities disguise themselves under the pretense of national asset unfreezing, national policies, and engineering projects, as well as blockchain virtual currencies and stablecoins, using high returns as bait to lure users into joining WeChat groups. Within these groups, users are encouraged to invite others, post suspicious links to download fraudulent apps, engage in daily check-ins, attend meetings and courses, and other brainwashing activities, ultimately leading to fraud. These actions seriously infringe upon users' property rights.Once such behavior is discovered and verified, the platform will take action based on relevant national laws and regulations, as well as the "Tencent WeChat Software License and Service Agreement" and "WeChat Personal Account Usage Specifications," among other platform agreements and rules. Depending on the severity of the violations, related accounts will be subject to a tiered approach to handling, with repeated offenders potentially facing permanent login restrictions, and confirmed violating WeChat groups will have their group functions disabled.
app_icon
ChainCatcher Building the Web3 world with innovations.