Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure

August 19, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: thehackernews.com

Threat Risk: High
Victim: macOS users and organizations
Incident: Deployment of MacSync Stealer via social engineering and rotating C2 infrastructure.
Impact: Theft of sensitive credentials, session cookies, and cloud configuration files.
Attacker: Unidentified threat actors
Analysis: The MacSync Stealer targets macOS users via ‘ClickFix’ social engineering, utilizing terminal-based commands to deploy its payload. It specifically targets high-value data, including macOS Keychain, AWS credentials, and Kubernetes configurations. The actors employ a rotating C2 infrastructure to evade detection, utilizing consistent URI patterns for data exfiltration.
Recommendations: Implement strict endpoint monitoring for unauthorized zsh and curl activities; Educate users on the risks of social engineering prompts that require executing terminal commands; Audit and rotate AWS and Kubernetes credentials if macOS compromise is suspected
Source: The Hacker News

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *