logo

Hunting MacSync Stealer infrastructure through behavioral pivots

ID: 499392f6-c347-51e4-be69-50e01171b3da

STIX ID: report--499392f6-c347-51e4-be69-50e01171b3da

Feed Name: Microsoft Security

Threat Score
70/100

Date Published: 2026-08-18

Date Updated: 2026-08-18

Author: Microsoft Defender Experts and Microsoft Security Research

...
...

**Executive summary:** Microsoft Defender Experts analyzed MacSync Stealer, a macOS information-stealing malware that leverages user-pasted Terminal commands (ClickFix social engineering), curl-based payload delivery, AppleScript-assisted execution, broad credential and file collection (Keychain, browser stores, SSH, cloud creds, user files), staging under /tmp paths, chunked HTTP PUT exfiltration with API-key headers and upload_id/chunk_index/total_chunks parameters, and rapidly rotating web infrastructure; the report provides behavioral pivots, >30 related domains as point-in-time IOCs, MITRE ATT&CK mappings, hunting queries, and recommended mitigations to detect and disrupt the activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.