CuraSec

tag: Domain-Pivoting · 1 items

2026-08-19 · Microsoft Security Blog · source ↗ #macos-stealer#threat-hunting#domain-pivoting
  • Engineer — Learn: MacSync Stealer targets macOS endpoints and could affect developer machines or macOS-based CI runners; no patch or configuration action exists, but understanding that this stealer rapidly rotates C2 domains should inform endpoint coverage decisions for macOS assets.
  • SOC/IR — Act: Microsoft’s analysis identifies 30+ MacSync Stealer-attributed domains via durable behavioral pivots; hunt for connections to those domains in DNS and proxy logs since the start of MacSync activity, and encode the stable behavioral signals as detections to survive future domain rotation.
  • Leader — Skip