MICROSOFT is tracking the MacSync Stealer malware by analyzing its behavior rather than individual domains, as the malware quickly rotates associated domains to evade detection. This macOS-focused information stealer targets valuable data such as passwords, keys, and wallet information. The infection method involves social engineering techniques that mislead victims into executing commands in the macOS Terminal to download malware payloads.
Microsoft identified key behavioral patterns linked to over 30 domains associated with the malware's infrastructure, revealing its functionality in command-and-control communication as well as data theft. After exfiltration, the malware cleans up by deleting temporary files, but its behavioral patterns remain identifiable, aiding in detection efforts against future attacks.