Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure

Summary

Microsoft Defender Experts have identified over 30 rotating web domains associated with MacSync Stealer, a malware targeting macOS. By analyzing endpoint and network behaviors, Microsoft was able to trace the malware's lifecycle from initial payload retrieval to data exfiltration.

IFF Assessment

FOE

The discovery of new infrastructure used by a macOS information stealer indicates an ongoing threat to users of that operating system, representing bad news for defenders.

Defender Context

This discovery highlights the evolving tactics of malware authors, who use rotating domains to evade detection and maintain operational control. Defenders should be vigilant in monitoring for connections to suspicious domains and have robust endpoint detection and response (EDR) solutions in place to identify and block malware like MacSync Stealer.

Read Full Story →