By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Microsoft Links 30+ Domains to MacSync Stealer

Microsoft Defender Experts have identified and linked more than 30 distinct web domains to the infrastructure of MacSync Stealer, a malware specifically designed to steal information from macOS devices. This attribution was achieved by correlating recurring endpoint and network behaviors observed across the malware's evolving operational infrastructure. The analysis traced the malware's lifecycle from the initial retrieval of its payload to the subsequent stages of data collection, staging, and eventual exfiltration of sensitive information. Microsoft stated that it was necessary to observe multiple endpoint and network behaviors in conjunction to establish a definitive link between these domains and the MacSync Stealer operations. The threat actor behind MacSync Stealer has demonstrated a pattern of rotating these domains to evade detection and maintain operational continuity. This tactic involves frequently changing the command-and-control (C2) servers that the malware communicates with, making it challenging for security researchers and automated defense systems to block the malicious infrastructure effectively. The MacSync Stealer malware is known to target a wide range of sensitive data stored on macOS systems, including login credentials for various applications and services, browser cookies, cryptocurrency wallet information, and other personally identifiable information. Once compromised, infected systems can be used to facilitate further malicious activities, such as identity theft, financial fraud, or as a pivot point for larger network intrusions. The continuous rotation of domains is a common evasion technique employed by sophisticated malware operators to prolong the lifespan of their campaigns and maximize their illicit gains. Microsoft's research highlights the persistent threat posed by macOS-specific malware and the importance of advanced threat detection capabilities that can analyze behavioral patterns rather than relying solely on static indicators of compromise like IP addresses or domain names. The Defender Experts team utilized a combination of telemetry data from endpoints and network traffic analysis to build a comprehensive picture of the MacSync Stealer's operational framework. By understanding these behavioral patterns, Microsoft aims to proactively identify and disrupt such malicious infrastructure, thereby protecting its users from potential data breaches and cyberattacks. The ongoing efforts by Microsoft and other cybersecurity firms are crucial in combating the evolving landscape of cyber threats, particularly those targeting less commonly attacked, yet increasingly popular, operating systems like macOS.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.