Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-20 ยท updated: 2026-08-20 ยท tags: [incident, infostealer, macos, clickfix, microsoft] ยท confidence: high ยท affected_sectors: [technology] ยท au_impact: true

Microsoft Ties 30+ Rotating Domains to MacSync Stealer Infrastructure

Microsoft Defender for Endpoint correlated more than 30 web domains to MacSync Stealer, a macOS-focused information stealer, tracing payload retrieval, staging and exfiltration over rotating infrastructure.

Attribute Detail
Actor infra 30+ rotating web domains (MacSync stealer)
Execution Interactive Terminal sessions consistent with ClickFix social engineering
Payload chain curl + native macOS utilities to retrieve/unpack payloads
Source Microsoft (via BleepingComputer) โ€” Tier 2/4

The campaign uses ClickFix social engineering to lure macOS users into running curl/native-command payloads, with rotating domain infrastructure to resist takedown.

Source