Threat Intelligence

Microsoft Uncovers 30+ Domains Linked to New Mac-Targeting Malware

The Hacker News · 19 Aug 2026
Key Takeaway If your business uses Mac computers, don't assume they're immune to malware—ensure endpoint protection software is installed and kept up to date on all devices, regardless of operating system.

Microsoft's security researchers have traced a network of more than 30 web domains connected to MacSync Stealer, a piece of malware designed specifically to steal information from Apple Mac devices. Rather than relying on a single fixed domain, the attackers behind this campaign rotate their infrastructure regularly, making it harder for traditional security tools to block them using simple blocklists.

Microsoft's Defender Experts team was able to connect these shifting domains by looking at recurring patterns in how the malware behaves on infected devices and across networks, rather than relying solely on the specific web addresses used. This allowed them to follow the full attack chain, from the initial delivery of the malicious payload through to how it collects, stores, and ultimately sends stolen data back to the attackers.

This discovery is a reminder that Mac computers are increasingly being targeted by cybercriminals, challenging the outdated assumption that Apple devices are largely immune to malware. As attackers use more sophisticated techniques like rotating infrastructure to evade detection, businesses using Macs need to ensure their security tools go beyond simple domain blocking.

macOS security infostealer malware Microsoft Defender

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.