Tag: Microsoft Links

Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure
News

Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure

After tracking the malware from payload retrieval through data collection, staging, and exfiltration, Microsoft Defender Experts have connected over thirty web domains to MacSync Stealer, a macOS-focused information stealer, by correlating recurrent endpoint and network behaviors across shifting infrastructure. Before classifying a domain as linked, the tech giant claimed that several endpoint and network behaviors, such as process ancestry, command-line patterns, request pathways, headers, and upload parameters, had to line up. In the study released on Tuesday, Microsoft did not provide the number of victims or link the activity to a specific threat actor. According to the corporation, the research also verified actual data exfiltration rather than just beaconing. The analysis s...