{
  "id": 1954945,
  "title": "Microsoft smothers malware by tracking behavior instead of blocking domains",
  "url": "https://urgent.news/2026/08/19/microsoft-smothers-malware-by-tracking-behavior-instead-of-blocking",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-19T14:20:00.000Z",
  "source": {
    "name": "TechRadar",
    "slug": "techradar",
    "url": "https://www.techradar.com/pro/security/microsoft-smothers-malware-by-tracking-behavior-instead-of-blocking-domains"
  },
  "original_language": "en",
  "account": "Microsoft has found a way to combat the MacSync Stealer malware by tracking its behavior instead of blocking specific domains. MacSync Stealer is a malicious software designed for Apple devices, which steals passwords, browser data, and other sensitive information. Initially, defenders attempted to protect Mac fleets by blocking domains hosting the malware, but this proved ineffective as new domains would appear once the old ones were blocked.\n\nMicrosoft's Defender experts analyzed behavioral patterns to identify over 30 domains involved in the malware's infrastructure. By examining recurring endpoints and network behaviors, they discovered that the infrastructure supported more than command-and-control (C2) communication, including active collection, staging, and exfiltration of data.\n\nTo defend against MacSync Stealer, Microsoft advises focusing on identifying suspicious shell sessions, osascript activity, and the presence of archives under /tmp/sync just before outbound PUT traffic begins. By monitoring these behaviors rather than blocking domains, defenders can better protect Mac devices from this dangerous malware.",
  "summary": "Blocking domains is a game of whack-a-mole in which attackers automate new moles popping up almost instantly.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "Computerworld",
        "title": "New malware turns Microsoft 365 and Azure into its control center",
        "url": "https://urgent.news/2026/08/18/new-malware-turns-microsoft-365-and-azure-into-its-control-center",
        "published": "2026-08-18T11:12:47.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}