Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure
ID: 8db32360-eac2-5f86-9134-93dbdff11ba5
STIX ID: report--8db32360-eac2-5f86-9134-93dbdff11ba5
Feed Name: The Hacker News
Microsoft Defender Experts correlated endpoint and network behaviors to link over 30 web domains to MacSync Stealer, a macOS information stealer that executes via user-pasted Terminal commands (ClickFix social engineering), uses native macOS utilities and AppleScript for execution, collects sensitive credentials (Keychain, browser cookies, SSH keys, AWS creds, etc.), stages and compresses data under /tmp, splits it into chunks, and uploads via HTTP PUT requests with recurring parameters and API-key headers; the report provides domain IOCs and hunting/detection guidance for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
