Microsoft Ties 30+ Domains to MacSync MacOS Information Stealer Infrastructure

1 min read
Source: The Hacker News
Microsoft Ties 30+ Domains to MacSync MacOS Information Stealer Infrastructure
Photo: The Hacker News
TL;DR Summary

Microsoft Defender Experts linked more than 30 web domains to the MacSync Stealer infrastructure, tracing a macOS information stealer from payload delivery through exfiltration. The campaign uses interactive zsh terminals, curl-based payload retrieval, AppleScript-assisted execution, and staging in /tmp with HTTP PUT uploads carrying chunked data. Observed exfiltration patterns and recurring endpoints (/curl/, /dynamic?txd=, /gate build) reveal rotating infrastructure, while data collected includes credentials, keys, and sensitive files. Microsoft cautions users and urges monitoring of curl uploads, API-key headers, and domain changes; Apple’s macOS protections (Terminal paste protection, pasteboard blocking, AppleScript scanning) are also relevant. The report follows similar findings from RST Cloud, which noted a static API key across several domains and parallel C2 operation across a rotating set of domains.

Share this article

Reading Insights

Total Reads

1

Unique Readers

6

Time Saved

3 min

vs 4 min read

Condensed

85%

801122 words

Want the full story? Read the original article

Read on The Hacker News