← Back to feed
Threat Actors & CampaignsEmerging1 sourceAug 18, 2026 · 17:08via Microsoft Security Blog

Hunting MacSync Stealer infrastructure through behavioral pivots

Brief

In this article

  • Activity overview
  • Discovery of additional rotating infrastructure
  • Attack chain overview
  • Mitigation and protection guidance
  • References
  • Learn more

MacSync Stealer is a macOS-focused information stealer that relies on changing infrastructure to deliver payloads, communicate with compromised devices, and exfiltrate data. Earlier reporting by RST Cloud identified the threat through a limited set of domains and documented rapid command-and-control (C2) replacement after public disclosure.

Microsoft Defender Experts expanded that view by correlating recurring endpoints and network behaviors across the activity. This behavior-led approach connected more than 30 domains and showed that the infrastructure supported more than C2 communication, extending into active collection, staging, and exfiltration.

Read more on Microsoft Security Blog