Microsoft Threat Intelligence
Microsoft Defender Experts’ analysis of MacSync Stealer, a macOS-focused infostealer that relies on constantly changing infrastructure for payload delivery, C2, and exfiltration, demonstrates that malicious domains rotate quickly, but attacker behavior often remains consistent. https://msft.it/6012azMLa By correlating recurring endpoint and network behaviors, including execution patterns, request characteristics, staging behavior, and upload methods, Microsoft Defender Experts uncovered related domains and identified durable detection and hunting pivots. Read our latest blog to learn how to hunt for MacSync Stealer beyond static indicators of compromise (IOCs), and get detection, mitigation, and hunting guidance to help investigate and respond to this threat.