Hunting MacSync Stealer infrastructure through behavioral pivots
Microsoft uncovered 30+ MacSync Stealer domains using behavioral pivots.
Summary
Microsoft Threat Intelligence has identified the MacSync Stealer malware, which employs a strategy of rapidly rotating domains to evade detection. Despite this, the malware's underlying behavior remains consistent, allowing Microsoft to uncover over 30 related domains through durable hunting pivots. This analysis highlights the persistent threat of macOS-targeting malware and the methods used to track its infrastructure.
Full text
August 10 20 min read DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure Microsoft Threat Intelligence examines DeadLock ransomware, an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications, negotiations, and data leak operations alongside double extortion tactics used to pressure victims.
Indicators of Compromise
- malware — MacSync Stealer