Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure
Microsoft Defender Experts have identified over 30 rotating web domains linked to the MacSync Stealer, a macOS-focused information stealer. The analysis correlated recurring endpoint and network behaviors to trace the malware's full lifecycle, from payload retrieval to da…
Intelligence analysis by Gemini 2.5 Flash

Microsoft's investigation revealed that the MacSync Stealer employs sophisticated tactics, including rapidly changing its command-and-control infrastructure across dozens of domains, to evade detection. By meticulously analyzing consistent behavioral patterns on endpoints and networks, Microsoft was able to connect these disparate domains to the same malicious operation, confirming ac…
Imagine a sneaky thief who keeps changing their secret hideout every day, making it hard for the police to catch them. This thief, called MacSync, tries to steal your digital secrets like passwords and private notes from your Mac computer. Microsoft, like a super detective, watched how the thief acted, not just where they hid, and found all their changing hideouts, helping to warn everyone about this clever trickster.
Analysis
Microsoft's recent findings significantly advance the understanding of the MacSync Stealer, a potent macOS threat. The tech giant's ability to link over 30 rotating domains to this single malicious infrastructure demonstrates a sophisticated approach to threat intelligence, moving beyond static indicators to dynamic behavioral analysis. This method allowed researchers to track the malware's full operational chain, from initial infection via social engineering to the final exfiltration of stolen data, even as its network footprint constantly shifted.
The investigation detailed the malware's execution flow, starting from an interactive zsh Terminal session, often initiated by ClickFix social engineering. It then uses curl to retrieve attacker-controlled content, followed by native utilities like Base64 and gunzip for decoding. The malware leverages osascript for AppleScript-assisted execution, collecting extensive host and user information, including macOS Keychain data, browser credentials, SSH keys, AWS credentials, and sensitive files, before compressing and exfiltrating it in chunks via HTTP PUT requests.
RST Cloud
Microsoft's analysis builds upon earlier work, notably RST Cloud's May 8 analysis, which initially documented a static API key across four confirmed command-and-control (C2) domains. RST Cloud also identified 11 additional candidate domains by observing recurring URI patterns such as /dynamic?txd= and /gate?buildtxd=. The overlap in submission windows for these candidates suggested parallel C2 operations rather than a strict sequential rotation, indicating a more robust and resilient infrastructure.
A comparison between the two sets of indicators revealed that four domains listed by Microsoft—lalandscapelighting[.]com, lumenagnet[.]com, nailscanai[.]com, and numericagent[.]com—were also part of RST Cloud's earlier candidate cluster. While RST Cloud classified these as URI-pattern bound due to a lack of sample validation for the static API key, Microsoft's subsequent investigation confirmed their connection. This collaboration and validation across security researchers strengthen the overall defense against such adaptive threats.
Apple
In response to evolving threats like MacSync, Apple has implemented several protective measures in macOS 26.4 and later versions. These include Terminal paste protection, pasteboard command blocking, and AppleScript scanning, all designed to mitigate the risks associated with malicious commands and scripts. Terminal paste protection, for instance, issues a warning under specific conditions, such as when a user hasn't opened Terminal in over 30 days or when the paste originates from a web browser or messaging app.
Furthermore, macOS's XProtect feature can trace the process tree generated by pasted terminal commands, cross-referencing associated network artifacts with Apple's Safe Browsing Service to block known malware techniques. Local inspection of AppleScript and JavaScript for Automation executions, even those directly from memory, adds another layer of defense. These built-in protections, combined with Microsoft's recommendations for user education and vigilant monitoring, form a multi-layered strategy to combat sophisticated macOS malware.
Key points
- Microsoft linked over 30 rotating web domains to the MacSync Stealer, a macOS information stealer.
- The malware collects sensitive data including macOS Keychain material, browser credentials, SSH keys, and AWS credentials.
- Initial infection often occurs via social engineering, leading to interactive zsh Terminal sessions.
- Data exfiltration involves compressing collected information and uploading it in chunks via HTTP PUT requests.
- Apple has implemented protections like Terminal paste protection and AppleScript scanning in macOS 26.4 and later to counter such threats.
The detailed analysis by Microsoft, building on prior research, significantly enhances the collective understanding of MacSync Stealer's operational tactics and infrastructure. This improved intelligence can lead to more effective detection mechanisms and better-informed security practices, ultimately strengthening defenses for macOS users and organizations against similar sophisticated threats.
Despite the detailed disclosure, the MacSync Stealer's use of rotating domains and social engineering tactics means it remains a persistent threat. Users might still fall victim to the initial social engineering lures, and the rapid infrastructure changes could continue to challenge traditional security solutions, requiring constant vigilance and adaptation from defenders.



