<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure]]></title><description><![CDATA[<p dir="auto"><strong>Title:</strong> Microsoft Ties Over 30 Rotating Domains to MacSync Stealer Campaign</p>
<p dir="auto"><strong>Summary:</strong> Microsoft Defender Experts have identified and linked more than 30 dynamic web domains to the MacSync Stealer, a macOS-specific information stealer. The attribution was achieved by correlating repeated endpoint and network behavioral patterns across shifting infrastructure, allowing researchers to track the malware's lifecycle from initial payload retrieval to data staging and exfiltration.</p>
<p dir="auto"><strong>Body:</strong></p>
<p dir="auto">Microsoft's threat intelligence team has published new findings connecting a network of more than 30 rotating domains to the MacSync Stealer, a credential and data-stealing malware targeting macOS systems. According to Microsoft Defender Experts, the attribution relied on aligning multiple endpoint and network signals, rather than a single static indicator.</p>
<p dir="auto">The investigation revealed that the operators behind MacSync Stealer frequently change their hosting infrastructure to evade detection. However, Microsoft observed recurring behavioral consistencies across these domains that linked them to the same malicious operation. These correlations allowed researchers to reconstruct the malware's operational flow, which spans distinct phases: the initial payload delivery, subsequent data collection, local staging of stolen files, and the final exfiltration to attacker-controlled servers.</p>
<p dir="auto">Microsoft noted that definitive attribution required a high-confidence convergence of several behavioral triggers from both the compromised endpoints and the network traffic generated by the malware. While the specific technical details of the behavioral signatures were not fully disclosed, the report emphasizes that the domains were not randomly associated but shared a distinct operational fingerprint with the MacSync Stealer family.</p>
<p dir="auto">Organizations running macOS environments are advised to review their security logs for connections to the identified domains and to monitor for unusual data staging or outbound transfer patterns that align with the described lifecycle.</p>
<p dir="auto"><strong>Source:</strong> The Hacker News<br />
<strong>Original Article:</strong> <a href="https://thehackernews.com/2026/08/microsoft-links-30-rotating-domains-to.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/08/microsoft-links-30-rotating-domains-to.html</a></p>
]]></description><link>https://xploitlk.com/topic/41/microsoft-links-30-rotating-domains-to-macsync-stealer-infrastructure</link><generator>RSS for Node</generator><lastBuildDate>Sat, 05 Sep 2026 11:43:19 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/41.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 19 Aug 2026 10:01:21 GMT</pubDate><ttl>60</ttl></channel></rss>