type: incident ยท created: 2026-08-20 ยท updated: 2026-08-20 ยท tags: [incident, infostealer, macos, clickfix, microsoft] ยท confidence: high ยท affected_sectors: [technology] ยท au_impact: true
Microsoft Ties 30+ Rotating Domains to MacSync Stealer Infrastructure
Microsoft Defender for Endpoint correlated more than 30 web domains to MacSync Stealer, a macOS-focused information stealer, tracing payload retrieval, staging and exfiltration over rotating infrastructure.
| Attribute | Detail |
|---|---|
| Actor infra | 30+ rotating web domains (MacSync stealer) |
| Execution | Interactive Terminal sessions consistent with ClickFix social engineering |
| Payload chain | curl + native macOS utilities to retrieve/unpack payloads |
| Source | Microsoft (via BleepingComputer) โ Tier 2/4 |
The campaign uses ClickFix social engineering to lure macOS users into running curl/native-command payloads, with rotating domain infrastructure to resist takedown.