Full Report
Microsoft Defender Experts have linked more than 30 web domains to MacSync Stealer, a macOS-focused information stealer, after correlating recurring endpoint and network behaviors across changing infrastructure, tracing the malware from payload retrieval through data collection, staging, and exfiltration. The tech giant said it required multiple endpoint and network behaviors to align before
Analysis Summary
# Morning News Roll-up August 19, 2026
## Overview
Microsoft Defender Experts have uncovered a sophisticated infrastructure linked to the MacSync Stealer malware, identifying over 30 rotating domains used for data exfiltration. The campaign primarily targets macOS users through social engineering and utilizes native system tools to harvest a wide array of sensitive credentials and personal data.
## Top Stories
### Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure
- Summary: Microsoft researchers correlated recurring endpoint and network behaviors to trace MacSync Stealer from payload delivery to data exfiltration. The malware uses native macOS utilities to steal Keychain data, browser credentials, and cloud configurations, exfiltrating the data via HTTP PUT requests to a rotating set of C2 domains.
- Source: hxxps://thehackernews[.]com/2026/08/microsoft-links-30-rotating-domains-to.html
### MacSync Stealer Infrastructure Rotation and Persistence
- Summary: Building on earlier research by RST Cloud, new findings confirm that MacSync Stealer operators use parallel command-and-control (C2) operations. While hex build tokens rotate per deployment, certain infrastructure traits like API-key headers and specific URI patterns remain consistent across the campaign.
- Source: hxxps://thehackernews[.]com/2026/08/microsoft-links-30-rotating-domains-to.html
### ClickFix Campaigns Distribute macOS Information Stealers
- Summary: The initial infection vector for MacSync Stealer has been identified as "ClickFix" social engineering, where users are prompted to run malicious commands in an interactive `zsh` Terminal session, leading to the deployment of the stealer payload.
- Source: hxxps://thehackernews[.]com/2026/03/clickfix-campaigns-spread-macsync-macos.html
---
# MacSync Stealer Infrastructure Analysis
## Key Points
- **Infrastructure Correlation:** Microsoft identified over 30 domains by aligning process ancestry, command-line patterns, and specific network upload parameters.
- **Active Exfiltration:** Confirmed active data theft rather than simple beaconing; data is chunked and uploaded using HTTP PUT requests.
- **Native Utility Abuse:** The malware leverages native macOS and Unix utilities including `curl`, `base64`, `gunzip`, and `osascript` (AppleScript) to minimize its footprint.
- **Data Staging:** Stolen information is temporarily stored in `/tmp/sync*` and compressed into a file named `osalogging.zip` before being split for transmission.
## Threat Actors
- **Attribution:** Not currently attributed to a named threat actor group.
- **Associated Campaigns:** Linked to "ClickFix" social engineering tactics.
- **Motivations:** Likely financial gain or cyber espionage, given the focus on harvesting AWS credentials, SSH keys, and Kubernetes configurations.
## TTPs
- **Initial Access:** Social engineering (ClickFix) prompting users to execute commands in a `zsh` terminal.
- **Execution:** Use of `osascript` for AppleScript execution and `curl` for payload retrieval via the `/curl/` path.
- **Credential Access:** Harvesting of macOS Keychain, browser cookies, SSH keys, AWS credentials, and Apple Notes.
- **Network Traffic:** Use of recurring URI patterns: `/dynamic?txd=` and `/gate?buildtxd=`.
- **Exfiltration:** Data is split into chunks and uploaded via HTTP PUT with parameters `upload_id`, `chunk_index`, and `total_chunks`.
- **Defense Evasion:** Automatic removal of temporary archives, staging folders, and lock files post-exfiltration.
## Affected Systems
- **Platforms:** Apple macOS.
- **Applications:** Web browsers (credentials/cookies), Keychain, AWS CLI, Kubernetes, and SSH clients.
- **Scope:** Broad targeting of macOS users, particularly those in technical or cloud-oriented roles.
## IoCs
- **C2 Domains:**
- `aihealthring[.]com`
- `cabinrentalsnc[.]com`
- `chatbasedos[.]com`
- `commercialroofingsd[.]com`
- `dogtrainersgeorgia[.]com`
- `fintelliganceai[.]com`
- `homeinspectionsdelaware[.]com`
- `intopython[.]com`
- `lalandscapelighting[.]com`
- `lumenagnet[.]com`
- `marbellaresales[.]com`
- `miamipcsupport[.]com`
- `moldinspectiondayton[.]com`
- `nailscanai[.]com`
- `newjerseypetsitter[.]com`
- `numericagent[.]com`
- `oaklandwaterdamage[.]com`
- `oklahomawarehousing[.]com`
- `olympiapetemergency[.]com`
- `peaecagent[.]com`
- `plasmaticsystems[.]com`
- `plethorawallet[.]com`
- `premierrentalpurchase[.]com`
- `ricewaterbeauty[.]com`
- `rvieragent[.]com`
- `sandiegotkd[.]com`
- `secueragent[.]com`
- `shiledagent[.]com`
- `syracusefertilitycenter[.]com`
- `vastbets[.]com`
- `wvaeagent[.]com`
- **File Artifacts:**
- `/tmp/sync*` (Staging directory)
- `/tmp/osalogging.zip` (Exfiltration archive)
## Mitigations
- **User Education:** Train users to recognize "ClickFix" social engineering prompts that ask them to copy/paste commands into a Terminal.
- **Endpoint Monitoring:** Monitor for suspicious `curl` activity involving unusual paths (e.g., `/curl/`, `/dynamic?txd=`) and HTTP PUT methods.
- **Process Auditing:** Audit the use of `osascript` and native utilities (`gunzip`, `base64`) when spawned by browser or terminal processes.
- **Network Filtering:** Block communication with the identified list of malicious domains.
## Conclusion
MacSync Stealer represents a significant threat to macOS environments due to its ability to harvest high-value cloud and development credentials. The use of rotating infrastructure and legitimate system utilities makes detection challenging. Organizations should focus on monitoring terminal-based execution patterns and anomalous outbound HTTP PUT traffic to mitigate the risk of data exfiltration.