Microsoft smothers malware by tracking behavior instead of blocking domains
Blocking domains is a game of whack-a-mole in which attackers automate new moles popping up almost instantly.
Microsoft has found a way to combat the MacSync Stealer malware by tracking its behavior instead of blocking specific domains. MacSync Stealer is a malicious software designed for Apple devices, which steals passwords, browser data, and other sensitive information. Initially, defenders attempted to protect Mac fleets by blocking domains hosting the malware, but this proved ineffective as new domains would appear once the old ones were blocked.
Microsoft's Defender experts analyzed behavioral patterns to identify over 30 domains involved in the malware's infrastructure. By examining recurring endpoints and network behaviors, they discovered that the infrastructure supported more than command-and-control (C2) communication, including active collection, staging, and exfiltration of data.
To defend against MacSync Stealer, Microsoft advises focusing on identifying suspicious shell sessions, osascript activity, and the presence of archives under /tmp/sync just before outbound PUT traffic begins. By monitoring these behaviors rather than blocking domains, defenders can better protect Mac devices from this dangerous malware.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.
- New malware turns Microsoft 365 and Azure into its control center computerworld.com