logo

Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure

ID: 8db32360-eac2-5f86-9134-93dbdff11ba5

STIX ID: report--8db32360-eac2-5f86-9134-93dbdff11ba5

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-08-19

Date Updated: 2026-08-20

Author: [email protected] (The Hacker News)

...
...

Microsoft Defender Experts correlated endpoint and network behaviors to link over 30 web domains to MacSync Stealer, a macOS information stealer that executes via user-pasted Terminal commands (ClickFix social engineering), uses native macOS utilities and AppleScript for execution, collects sensitive credentials (Keychain, browser cookies, SSH keys, AWS creds, etc.), stages and compresses data under /tmp, splits it into chunks, and uploads via HTTP PUT requests with recurring parameters and API-key headers; the report provides domain IOCs and hunting/detection guidance for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.