Microsoft Ties 30+ Rotating Domains to MacSync, a New Mac Data-Stealing Malware
Defender Experts traced the macOS stealer across shifting web infrastructure by matching endpoint and network behaviour, not just domain names.

Key points
- Microsoft Defender Experts have linked more than 30 web domains to MacSync Stealer, a piece of malicious software built to steal data from Apple Mac computers.
- The malware was tracked across the full attack chain: fetching its payload, collecting data, staging it locally, then sending it back to the attackers.
- Microsoft says it identified the network only after several endpoint and network behaviours lined up together, not by relying on a single indicator.
- MacSync is an information stealer, software designed to quietly copy passwords, browser data and files off an infected machine.
- The domains rotate frequently, a tactic used to stay ahead of blocklists maintained by security vendors.
Microsoft has connected more than 30 internet domains to a single macOS information stealer known as MacSync, according to research published by its Defender Experts team.
An information stealer is malicious software that silently copies sensitive data from a computer: saved browser passwords, session cookies that keep you logged in, cryptocurrency wallet files, documents. It then ships that data to a server the criminals control. MacSync is one of a small but growing number of stealers built specifically for Apple's Mac computers, which have historically seen less of this activity than Windows machines. We covered a similar Mac stealer just days earlier in AmnesiaStealer, published 14 August 2026.
The headline finding isn't the malware itself. It's how Microsoft found the infrastructure behind it.
How did Microsoft link the domains together?
By correlating behaviour rather than chasing individual domain names. Microsoft's team watched what infected Macs did, on the device and on the network, and required several of those behaviours to line up before attributing a domain to the same operation.
That matters because the attackers rotate their domains often. A single domain, taken on its own, looks like noise. Microsoft's analysts traced the malware through four stages: fetching the initial payload, collecting data from the Mac, staging that data in a temporary location, then exfiltrating it to the attacker's server.
When the same sequence of endpoint actions kept pairing with fresh domains, the team could bundle those domains together as one campaign. The result, as first reported by The Hacker News, is a map of more than 30 domains tied to MacSync.
What is MacSync Stealer?
MacSync is malware targeting macOS, designed to harvest data from the machines it infects. Microsoft's writeup describes activity across the full stealer lifecycle, from the moment a payload lands on the Mac to the moment stolen data leaves the network.
Mac-focused stealers have grown noticeably over the past two years. They typically arrive dressed as cracked software or fake app installers. Once running, they read from browsers and wallet software, then package the contents for upload. Microsoft hasn't published a full technical teardown of MacSync in the excerpt available, but the behavioural pattern it describes is consistent with that broader family.
What does this mean for ordinary Mac users?
Be cautious about where your software comes from. Most Mac stealers don't exploit a hidden flaw in macOS itself. They rely on the user being persuaded to run something they shouldn't have run.
Install apps from the Mac App Store or directly from the developer's official site, not from a link in an ad or a forum post. Treat any prompt asking for your Mac password during an install with suspicion, especially from software downloaded moments earlier. Keep macOS and your browser current so built-in protections like Gatekeeper and XProtect stay active.
If you think a Mac has run something suspicious, change passwords for important accounts from a different device and sign out of active sessions in services like email and cloud storage.
Should you worry about rotating domains?
Rotating domains defeat blocklists. Behavioural correlation does not. Microsoft's approach here, tying network indicators to on-device behaviour before making a link, is the method defenders increasingly rely on when the outer shell of an attack changes faster than any list can be updated. Our earlier story on fake Mac download domains showed a network using more than 250 domains to screen out researchers. MacSync's operators are playing the same rotation game with a smaller deck. Watch whether Microsoft moves to publish behavioural detection rules that other vendors can adopt: that's the step that would turn this research into a practical defence.



