Microsoft Identifies Over 30 Domains Linked to MacSync Stealer Malware

Microsoft Identifies Over 30 Domains Linked to MacSync Stealer Malware

First seen 19 Aug 2026, 11:10 UTC ThehackernewsGbhackers 76% similarity 51.9

Article Content

Browse articles
ThreatCluster

Microsoft has linked more than 30 rotating domains to the MacSync Stealer, a malware targeting macOS systems. This infrastructure supports various malicious activities, including credential theft and data exfiltration. The malware operates through interactive zsh sessions and utilizes curl to fetch payloads. The investigation emphasizes the need for defenders to focus on behavioral detection methods rather than solely relying on static domain-based approaches. The ongoing threat poses risks to users of macOS devices, highlighting the necessity for enhanced security measures.

Key Points: • Over 30 domains associated with MacSync Stealer malware identified by Microsoft. • Malware targets macOS systems, facilitating credential theft and data exfiltration. • Defenders advised to prioritize behavioral detection over static domain monitoring.

ThreatCluster AI How this analysis works

Timeline

2026-08-19
Microsoft links domains to MacSync Stealer
Microsoft's investigation reveals over 30 domains used in a rotating infrastructure for credential theft and data exfiltration targeting macOS.
Gbhackers
2026-08-19
Malware execution methods detailed
The MacSync Stealer executes through interactive zsh sessions and uses curl for payload delivery, indicating sophisticated operational tactics.
Thehackernews

Community

Browse all →

Tracked Entities in This Story