Microsoft Ties 30+ Rotating Domains to MacSync, a New Mac Data-Stealing Malware

Defender Experts traced the macOS stealer across shifting web infrastructure by matching endpoint and network behaviour, not just domain names.

ThreatVectr Newsdesk· 4 min read
Full-frame overhead view of a modern silver laptop on a dark wooden desk, screen showing a blurred generic system password dialog with a red warning glow, apps
Share

Key points

  • Microsoft Defender Experts have linked more than 30 web domains to MacSync Stealer, a piece of malicious software built to steal data from Apple Mac computers.
  • The malware was tracked across the full attack chain: fetching its payload, collecting data, staging it locally, and sending it back to the attackers.
  • Microsoft says it identified the network only after several endpoint and network behaviours lined up together, not by relying on a single indicator.
  • MacSync is an information stealer, meaning software designed to quietly copy passwords, browser data and files off an infected machine.
  • The domains rotate frequently, a common tactic used to stay ahead of blocklists maintained by security vendors.

Microsoft has connected a sprawling web of more than 30 internet domains to a single macOS information stealer known as MacSync, according to research published by its Defender Experts team.

An information stealer is malicious software that silently copies sensitive data from a computer, things like saved browser passwords, session cookies that keep you logged in, cryptocurrency wallet files, and documents, then ships that data to a server the criminals control. MacSync is one of a small but growing number of stealers built specifically for Apple's Mac computers, which have historically seen less of this activity than Windows machines.

The headline finding is not the malware itself. It is how Microsoft found the infrastructure behind it.

How did Microsoft link the domains together?

By correlating behaviour rather than chasing individual domain names. Microsoft's team watched what infected Macs actually did, on the device and on the network, and required several of those behaviours to line up before attributing a domain to the same operation.

That matters because the attackers rotate their domains often. A single domain, taken on its own, looks like noise. Microsoft says its analysts traced the malware through four stages: fetching the initial payload, collecting data from the Mac, staging that data in a temporary location, and then exfiltrating it, meaning sending it out to the attacker's server.

When the same sequence of endpoint actions kept pairing with fresh domains, the team could bundle those domains together as one campaign. The result, as first reported by The Hacker News, is a map of more than 30 domains tied to MacSync.

What is MacSync Stealer?

MacSync is malware that targets macOS and is designed to harvest data from the machines it infects. Microsoft's writeup describes activity across the full stealer lifecycle, from the moment a payload lands on the Mac to the moment stolen data leaves the network.

Mac-focused stealers have grown noticeably over the past two years. They typically arrive dressed up as cracked software, fake app installers, or lures pushed through search-engine ads. Once running, they read from browsers, messaging apps, and wallet software, then package the contents for upload.

Microsoft has not published a full technical teardown of MacSync in the excerpt available, but the behavioural pattern it describes is consistent with that broader family of macOS stealers.

What does this mean for ordinary Mac users?

Be cautious about where your software comes from. Most Mac stealers do not exploit a hidden flaw in macOS itself. They rely on the user being persuaded to run something they should not have run.

A few practical habits go a long way:

  • Install apps from the Mac App Store or directly from the developer's official site, not from a link in an ad or a forum post.
  • Treat any prompt asking for your Mac password during an install with suspicion, especially from software you downloaded moments earlier.
  • If you use a browser password manager, consider moving to a dedicated password manager with a separate master password, which stealers cannot pull out of the browser store.
  • Keep macOS and your browser on the current version so built-in protections like Gatekeeper and XProtect stay up to date.

If you think a Mac has run something suspicious, change passwords for important accounts from a different device, and sign out of active sessions in services like email, banking, and cloud storage.

Why the detection approach is worth noting

Rotating domains defeat blocklists. Behavioural correlation does not. Microsoft's approach here, tying network indicators to on-device behaviour before making a link, is the same method defenders increasingly rely on when the outer shell of an attack changes faster than any list can be updated.

© 2026 Threat Vectr