Published on August 19, 2026

Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure


Severity
High

Detail

Microsoft Defender Experts have identified more than 30 rotating domains associated with MacSync Stealer, a macOS-focused information-stealing malware. Microsoft linked the infrastructure by correlating repeated endpoint and network behaviors across changing domains rather than relying solely on static indicators. MacSync Stealer is designed to collect sensitive information from compromised macOS devices, including credentials, browser data, cryptocurrency wallet information, and other sensitive files. The malware uses frequently changing infrastructure to make traditional domain-based detection and blocking less effective.

How?

MacSync Stealer uses multiple domains as part of its malware delivery, command-and-control, staging, and data-exfiltration infrastructure. Microsoft observed that the domains rotate over time, allowing the attackers to replace infrastructure when domains are blocked or identified by security teams.

Once executed on a macOS device, the malware performs a series of endpoint and network activities associated with collecting sensitive information. Stolen data is staged and subsequently exfiltrated to attacker-controlled infrastructure in chunks, making the traffic less dependent on a single persistent domain.

Microsoft’s investigation identified more than 30 domains connected through consistent behavioral patterns. The findings highlight that blocking individual domains may provide only temporary protection because the threat actors can rapidly rotate their infrastructure.

The campaign can potentially result in the theft of stored credentials, authentication information, cryptocurrency wallet data, and sensitive files from affected Mac devices. Compromised credentials may subsequently be used for unauthorized access to additional accounts and services.

Recommendation

Organizations should implement a layered security approach to reduce the risk of MacSync Stealer infections:

  • Keep macOS and security software updated with the latest security patches.
  • Monitor macOS endpoints for suspicious processes, unusual Terminal activity, and unexpected outbound connections.
  • Block known MacSync Stealer domains and continuously update threat intelligence indicators.
  • Monitor for unusual access to browser credentials, cryptocurrency wallets, and sensitive files.
  • Use endpoint detection and response (EDR) to detect suspicious malware behavior rather than relying only on domain-based blocking.
  • Investigate endpoints communicating with multiple newly identified or suspicious domains associated with MacSync Stealer activity.

Source

https://thehackernews.com/2026/08/microsoft-links-30-rotating-domains-to.html