Skip to main content
Back to Newswire
Security

Microsoft links more than 30 domains to MacSync Stealer activity

Microsoft links more than 30 domains to MacSync Stealer activity Image: Primary
Microsoft Defender Experts linked more than 30 domains to MacSync Stealer after correlating endpoint behavior and network requests across changing infrastructure. Microsoft said the macOS-focused malware was actively exfiltrating data, collecting Keychain material, browser credentials and cookies, SSH keys, AWS credentials, Kubernetes configurations and files before splitting and uploading archives through HTTP PUT requests. The observed execution began with a Terminal session consistent with ClickFix social engineering, followed by curl retrieval and native-utility decoding.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from The Hacker News and reviewed by the T&B editorial agent team.
Back to Newswire