Skip to main content

Hunting MacSync Stealer infrastructure through behavioral pivots

0
High
Published: 08/18/2026 (08/18/2026, 17:08:28 UTC)
Source: Microsoft Security Blog

Description

MacSync Stealer is a macOS-targeted information stealer that uses rapidly rotating infrastructure to deliver payloads, communicate with compromised devices, and exfiltrate stolen data. It employs social engineering to trick users into executing commands that retrieve and run malicious payloads. The malware collects sensitive information including macOS Keychain data, browser credentials, SSH keys, and files from user directories. Data is staged, compressed, split into chunks, and exfiltrated via HTTP PUT requests to attacker-controlled domains that frequently change. Despite domain rotation, consistent behavioral patterns in network requests, command-line usage, and process execution provide reliable detection and hunting opportunities. Microsoft Defender Experts identified over 30 related domains by correlating these recurring traits across the attack chain. The attack chain includes payload retrieval, command-and-control communication, data collection, staging, exfiltration, and cleanup.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/11/2026, 08:04:03 UTC

Technical Analysis

MacSync Stealer is a macOS-focused information stealer that relies on changing infrastructure to deliver payloads, communicate with compromised devices, and exfiltrate data. It begins with social engineering that leads to execution of attacker-controlled payloads via curl commands. The malware communicates with attacker infrastructure using consistent URI paths, macOS User-Agent strings, API-key headers, and curl command-line options, which serve as durable behavioral pivots despite rotating domains. It collects sensitive data such as Keychain material, browser data, credentials, and files, stages and compresses this data, splits it into chunks, and uploads it using HTTP PUT requests with identifiable parameters. Microsoft Defender Experts correlated multiple endpoint and network behaviors to link over 30 domains supporting the malware's infrastructure. This behavior-led approach enables defenders to track and investigate MacSync Stealer activity beyond static domain blocking.

Potential Impact

The malware compromises macOS devices by stealing sensitive information including Keychain data, browser credentials, SSH keys, and files from user directories. It actively exfiltrates collected data to attacker-controlled infrastructure, potentially leading to credential theft, unauthorized access, and data breaches. The use of rapidly rotating domains complicates detection and blocking but consistent behavioral patterns provide defenders with reliable detection opportunities. There is no indication of active exploitation in the wild beyond observed activity, and no direct mention of system integrity compromise or ransomware.

Defensive Guidance

No official patch or fix is indicated as this is malware rather than a software vulnerability. Mitigation focuses on detection and response using behavioral indicators such as recurring URI paths (/curl/, /dynamic?txd=, /gate?buildtxd=), specific curl command-line options (-k, -s, –max-time, –data-binary), macOS User-Agent strings, API-key headers, and HTTP PUT upload parameters (upload_id, chunk_index, total_chunks). Defenders should leverage endpoint and network telemetry to identify these patterns and investigate related activity. Blocking individual domains is less effective due to rapid rotation; instead, focus on behavioral detection and correlation across the attack chain. Users should be educated to avoid running untrusted commands in Terminal, especially those received via social engineering.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.77,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://www.microsoft.com/en-us/security/blog/2026/08/18/hunting-macsync-stealer-infrastructure-through-behavioral-pivots/","fetched":true,"fetchedAt":"2026-08-19T17:53:48.028Z","wordCount":4402}

Threat ID: 6a85edb4acd9273b49697439

Added to database: 08/19/2026, 17:53:56 UTC

Last enriched: 09/11/2026, 08:04:03 UTC

Last updated: 10/02/2026, 09:10:08 UTC

Views: 77

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses