Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure
Summary
Microsoft Defender Experts have identified over 30 rotating web domains associated with MacSync Stealer, a malware targeting macOS. By analyzing endpoint and network behaviors, Microsoft was able to trace the malware's lifecycle from initial payload retrieval to data exfiltration.
IFF Assessment
The discovery of new infrastructure used by a macOS information stealer indicates an ongoing threat to users of that operating system, representing bad news for defenders.
Defender Context
This discovery highlights the evolving tactics of malware authors, who use rotating domains to evade detection and maintain operational control. Defenders should be vigilant in monitoring for connections to suspicious domains and have robust endpoint detection and response (EDR) solutions in place to identify and block malware like MacSync Stealer.