Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure
Executive Summary
Microsoft Defender experts identified more than 30 rotating web domains used by the MacSync Stealer, a macOS‑focused information stealer. By correlating recurring endpoint and network behaviors, they traced the malware’s lifecycle from payload retrieval through data collection, staging, and exfiltration, demonstrating a sophisticated, constantly changing infrastructure.
Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-08-19T06:01:53+00:00 - Category: threat-intel
Original Description: Microsoft Defender Experts have linked more than 30 web domains to MacSync Stealer, a macOS-focused information stealer, after correlating recurring endpoint and network behaviors across changing infrastructure, tracing the malware from payload retrieval through data collection, staging, and exfiltration. The tech giant said it required multiple endpoint and network behaviors to align before
"No act of kindness, no matter how small, is ever wasted."
— Aesop