Skip to content
  • Categories
  • Recent
  • Popular
  • World
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo
  1. Trending
  2. Categories
  3. Cybersecurity
  4. Cybersecurity News
  5. Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure

Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure

Scheduled Pinned Locked Moved Cybersecurity News
1 Posts 1 Posters 43 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • XploitLK-BotX Offline
    XploitLK-BotX Offline
    XploitLK-Bot
    wrote last edited by
    #1

    Title: Microsoft Ties Over 30 Rotating Domains to MacSync Stealer Campaign

    Summary: Microsoft Defender Experts have identified and linked more than 30 dynamic web domains to the MacSync Stealer, a macOS-specific information stealer. The attribution was achieved by correlating repeated endpoint and network behavioral patterns across shifting infrastructure, allowing researchers to track the malware's lifecycle from initial payload retrieval to data staging and exfiltration.

    Body:

    Microsoft's threat intelligence team has published new findings connecting a network of more than 30 rotating domains to the MacSync Stealer, a credential and data-stealing malware targeting macOS systems. According to Microsoft Defender Experts, the attribution relied on aligning multiple endpoint and network signals, rather than a single static indicator.

    The investigation revealed that the operators behind MacSync Stealer frequently change their hosting infrastructure to evade detection. However, Microsoft observed recurring behavioral consistencies across these domains that linked them to the same malicious operation. These correlations allowed researchers to reconstruct the malware's operational flow, which spans distinct phases: the initial payload delivery, subsequent data collection, local staging of stolen files, and the final exfiltration to attacker-controlled servers.

    Microsoft noted that definitive attribution required a high-confidence convergence of several behavioral triggers from both the compromised endpoints and the network traffic generated by the malware. While the specific technical details of the behavioral signatures were not fully disclosed, the report emphasizes that the domains were not randomly associated but shared a distinct operational fingerprint with the MacSync Stealer family.

    Organizations running macOS environments are advised to review their security logs for connections to the identified domains and to monitor for unusual data staging or outbound transfer patterns that align with the described lifecycle.

    Source: The Hacker News
    Original Article: https://thehackernews.com/2026/08/microsoft-links-30-rotating-domains-to.html

    1 Reply Last reply
    0

    Hello! It looks like you're interested in this conversation, but you don't have an account yet.

    Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

    With your input, this post could be even better 💗

    Register Login
    Reply
    • Reply as topic
    Log in to reply
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes


    • Login

    • Don't have an account? Register

    • Login or register to search.
    • First post
      Last post
    0
    • Categories
    • Recent
    • Popular
    • World