[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$ffwAdFEufRofZNWyzaOC_FcP7awRzh4yhNXf76jDnzs0":3},{"article":4,"iocs":39},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":21,"category":22,"article_tags":26},"af159448-8924-4a18-8f7c-dff305d82c6e","Hunting MacSync Stealer infrastructure through behavioral pivots","hunting-macsync-stealer-infrastructure-through-behavioral-pivots-cd63a9","MacSync Stealer rapidly rotates domains to evade detection, but its behavior remains consistent. Learn how Microsoft uncovered 30+ related domains using durable hunting pivots. The post Hunting MacSync Stealer infrastructure through behavioral pivots appeared first on Microsoft Security Blog.","Microsoft Threat Intelligence has identified the MacSync Stealer malware, which employs a strategy of rapidly rotating domains to evade detection. Despite this, the malware's underlying behavior remains consistent, allowing Microsoft to uncover over 30 related domains through durable hunting pivots. This analysis highlights the persistent threat of macOS-targeting malware and the methods used to track its infrastructure.","Microsoft uncovered 30+ MacSync Stealer domains using behavioral pivots.","August 10 20 min read DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure Microsoft Threat Intelligence examines DeadLock ransomware, an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications, negotiations, and data leak operations alongside double extortion tactics used to pressure victims.","https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fsecurity\u002Fblog\u002F2026\u002F08\u002F18\u002Fhunting-macsync-stealer-infrastructure-through-behavioral-pivots\u002F","https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fsecurity\u002Fblog\u002Fwp-content\u002Fuploads\u002F2026\u002F05\u002FMS_Actional-Insights_Links.jpg","2026-08-18T17:08:28+00:00","2026-08-18T20:00:27.430155+00:00",7,[18],{"name":19,"type":20},"Microsoft","product","89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":21,"icon":23,"name":24,"slug":25},null,"Malware","malware",[27,32,34],{"category":28},{"id":29,"icon":23,"name":30,"slug":31},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":33},{"id":21,"icon":23,"name":24,"slug":25},{"category":35},{"id":36,"icon":23,"name":37,"slug":38},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[40],{"type":25,"value":41,"context":42},"MacSync Stealer","Identified malware family"]