Microsoft Uncovers 30+ Domains Linked to New Mac-Targeting Malware
Microsoft's security researchers have traced a network of more than 30 web domains connected to MacSync Stealer, a piece of malware designed specifically to steal information from Apple Mac devices. Rather than relying on a single fixed domain, the attackers behind this campaign rotate their infrastructure regularly, making it harder for traditional security tools to block them using simple blocklists.
Microsoft's Defender Experts team was able to connect these shifting domains by looking at recurring patterns in how the malware behaves on infected devices and across networks, rather than relying solely on the specific web addresses used. This allowed them to follow the full attack chain, from the initial delivery of the malicious payload through to how it collects, stores, and ultimately sends stolen data back to the attackers.
This discovery is a reminder that Mac computers are increasingly being targeted by cybercriminals, challenging the outdated assumption that Apple devices are largely immune to malware. As attackers use more sophisticated techniques like rotating infrastructure to evade detection, businesses using Macs need to ensure their security tools go beyond simple domain blocking.