Urgent.News

What's breaking now, across thousands of outlets.

Editions

Tech

MacSync rotates domains as macOS credential theft expands

MacSync Stealer has been linked to more than 30 rotating web domains as its operators broaden a macOS credential-theft campaign designed to evade conventional defences while maintaining recognisable execution, collection and data-transfer patterns. The malware targets passwords, browser credentials, authentication cookies, macOS Keychain material, SSH keys, cloud access credentials,…

The MacSync Stealer malware has been associated with over 30 distinct web domains as its creators expand a macOS credential-stealing campaign aimed at evading standard defenses while maintaining consistent execution, collection, and data-transfer methods. This malicious software targets various types of sensitive data, including passwords, browser credentials, authentication cookies, macOS Keychain content, SSH keys, cloud access credentials, cryptocurrency wallets, and files stored on affected machines.

To avoid detection, the operators of MacSync frequently change their command-and-control infrastructure, rendering individual domain blocklists less effective while preserving behaviors that can be tracked by defenders across multiple deployments.

Typically, MacSync infiltrates systems through social engineering tactics that involve deceptive websites or advertisements prompting users to copy and paste commands into the macOS Terminal. Users may be led to believe that they are installing software or resolving technical issues. However, this simple action initiates a malicious script-driven infection chain without the victim having to launch any unsigned application.

This approach aligns with a broader trend among macOS information stealers, who are increasingly exploiting trusted system utilities instead of relying on executable files that security solutions can more easily identify.

Similar campaigns have employed various techniques, such as malicious disk images, fraudulent installers, and advertisements masquerading as legitimate software, particularly targeting developers and technology enthusiasts. Once the malware is executed, it employs shell processes and AppleScript-assisted commands to gather information about the compromised machine and its user.

Collection may encompass passwords and credentials stored by web browsers, browser cookies and session data, Keychain information, Apple Notes, browsing history, Telegram data, and files from frequently used directories. MacSync has demonstrated a particular interest in developer environments, monitoring for SSH credentials, Amazon Web Services access material, and Kubernetes configuration files.

The theft of such credentials may extend the compromise beyond a single Mac, as valid developer or administrator keys can grant access to source-code repositories, servers, cloud services, and production infrastructure. Some more advanced variants of MacSync can also exhibit capabilities associated with persistent remote access and attempts to interfere with wallet applications, potentially causing more significant consequences beyond basic password collection.

Collected data is typically stored in temporary staging directories, with names beginning with /tmp/sync. The malware then creates an archive, often using /tmp/osalogging.zip, and splits the stolen material into smaller chunks for transmission. Exfiltration is carried out through curl using HTTP PUT requests, complete with repeated parameters like uploadid, chunkindex, and total_chunks to enable multipart uploads.

Additionally, this malware sends API-key headers, follows recurring request paths, and uses characteristic command-line options, generating behavioral indicators that remain useful even when the destination domains change. A May investigation revealed that a single command-and-control domain was replaced within days of being exposed.

New TLS certificates were issued approximately a day after the previous infrastructure was disclosed, and the replacement server quickly began attempting to deliver malicious content. Investigators connected multiple confirmed domains through a common API key and recurring URI structures. Further infrastructure dating back to at least February 2026 was identified through these patterns.

In recent analysis, over 30 distinct domains have been associated with behavior matching the MacSync campaign. These domains often resemble legitimate services, local businesses, software products, and technology projects, helping the malicious servers appear less conspicuous in standard network logs while allowing operators to quickly abandon exposed domains and activate replacements.

The campaign underscores the diminishing effectiveness of domain-based indicators in rapidly evolving malware operations. While blocking an identified server can disrupt an individual infection path, attackers can easily register and deploy replacement domains to restore operations swiftly. Defenders are shifting their focus towards analyzing correlations between endpoint and network behavior.

Unusual Terminal sessions followed by suspicious curl commands, AppleScript execution, access to credential stores, creation of temporary archives, and immediate outbound uploads can serve as stronger indicators of compromise than a single domain name. Administrators should also monitor macOS systems for abnormal access to Keychain data, browser credential databases, SSH directories, AWS files, and Kubernetes configurations.

Moreover, HTTP PUT requests containing chunk-management parameters or atypical API-key headers can help identify exfiltration attempts.

Written by urgent.news from Arabian Post's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at thearabianpost.com →

More in Tech

NITDA, Budget Office launch joint committee to drive Nigeria’s National Sovereign Cloud Initiative

The National Information Technology Development Agency and the Budget Office of the Federation have inaugurated a Joint Technical Committee to drive the implementation of Nigeria's National Sovereign…

  • NITDA and Budget Office form Joint Technical Committee
  • Committee chaired by Budget Office DG Tanimu Yakubu
  • Focus areas include fiscal, procurement, and investment structures

More from Friday 21 August →