securityaffairs.com 8/19/2026, 10:21:17 AM · external

Microsoft Tracks MacSync Stealer via Behaviour as Domains Rotate

Microsoft Tracks MacSync Stealer via Behaviour as Domains Rotate
Developing story malware 2 articles tracked
Microsoft tracks rotating domains linked to MacSync stealer campaign
CyberSIXT Evidence Panel
Primary Source microsoft.com

MICROSOFT is tracking the MacSync Stealer malware by analyzing its behavior rather than individual domains, as the malware quickly rotates associated domains to evade detection. This macOS-focused information stealer targets valuable data such as passwords, keys, and wallet information. The infection method involves social engineering techniques that mislead victims into executing commands in the macOS Terminal to download malware payloads.

Microsoft identified key behavioral patterns linked to over 30 domains associated with the malware's infrastructure, revealing its functionality in command-and-control communication as well as data theft. After exfiltration, the malware cleans up by deleting temporary files, but its behavioral patterns remain identifiable, aiding in detection efforts against future attacks.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline