Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Lloyd’s Register assists with LNG carrier-to-FSU conversion for African gas project

    August 19, 2026

    ProPublica Is Reporting on the Pentagon’s $1 Trillion Budget — ProPublica

    August 19, 2026

    Contemplating death helps us to really value life | Death and dying

    August 19, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Lloyd’s Register assists with LNG carrier-to-FSU conversion for African gas project
    • ProPublica Is Reporting on the Pentagon’s $1 Trillion Budget — ProPublica
    • Contemplating death helps us to really value life | Death and dying
    • Is the government on course to end rough sleeping? – Full Fact
    • Democrat Mary Peltola and Republican Dan Sullivan lead in Alaska primary for US Senate – US politics live | US politics
    • French civil servant drugged us to make us urinate on ourselves, say accusers
    • Threatening Friends and Courting Enemies in Trump’s ‘Upside-Down World’
    • Why Democrats and Republicans Are Backing Rivals in Alaska’s Senate Primary
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, August 19
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 19, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Microsoft Defender Experts have linked more than 30 web domains to MacSync Stealer, a macOS-focused information stealer, after correlating recurring endpoint and network behaviors across changing infrastructure, tracing the malware from payload retrieval through data collection, staging, and exfiltration.

    The tech giant said it required multiple endpoint and network behaviors to align before treating a domain as connected, including process ancestry, command-line patterns, request paths, headers, and upload parameters.

    Microsoft did not disclose a victim count or attribute the activity to a named threat actor in the report published Tuesday. “The investigation also confirmed active data exfiltration, not just beaconing,” the company said.

    According to the analysis, observed execution began from an interactive zsh Terminal session consistent with ClickFix social engineering, followed by curl retrieving attacker-controlled content over a recurring /curl/ path and native utilities such as Base64 and gunzip decoding or unpacking the payload.

    Cybersecurity

    The payload uses osascript for AppleScript-assisted execution alongside native macOS and Unix utilities, before collecting host and user information, macOS Keychain material, browser credentials and cookies, session data, Apple Notes, Secure Shell (SSH) keys, Amazon Web Services (AWS) credentials, Kubernetes configurations, browser history, and sensitive files from common user directories.

    Collected data is staged under /tmp/sync*, compressed into /tmp/osalogging.zip, split into multiple chunks, and uploaded with curl through HTTP PUT requests using recurring parameters such as upload_id, chunk_index, and total_chunks. The malware removes temporary archives, staging folders, lock files, and other artifacts after exfiltration.

    The disclosure builds on RST Cloud’s May 8 analysis, which documented a static API key across four confirmed command-and-control (C2) domains and identified 11 additional candidate domains through recurring /dynamic?txd= and /gate?buildtxd= URI patterns.

    Several candidates had overlapping submission windows, which RST Cloud said was consistent with parallel C2 operation rather than strict sequential rotation between hostnames. “The hex build token rotates per deployment, the api-key does not,” RST Cloud said.

    A comparison of the two published indicator sets by The Hacker News found that four domains Microsoft now lists, lalandscapelighting[.]com, lumenagnet[.]com, nailscanai[.]com, and numericagent[.]com, also appeared in RST Cloud’s May candidate cluster. RST Cloud classified those domains as URI-pattern bound rather than API-key confirmed because it had not retrieved samples from each candidate to validate the static API-key match.

    Microsoft refers to API-key headers as a recurring MacSync trait, but its August 18 post does not publish the static value documented by RST Cloud or state that the same value appears across every domain in the current set.

    Microsoft said the recurring network traits include the /curl/, /dynamic?txd=, and /gate?buildtxd= paths, macOS User-Agent strings, API-key headers, and HTTP PUT uploads carrying the same chunk-management parameters.

    The researchers used those request shapes together with endpoint execution context to identify related infrastructure as the domains changed.

    Microsoft shared the following point-in-time domain indicators observed in activity consistent with MacSync Stealer –

    • aihealthring[.]com
    • cabinrentalsnc[.]com
    • chatbasedos[.]com
    • commercialroofingsd[.]com
    • dogtrainersgeorgia[.]com
    • fintelliganceai[.]com
    • homeinspectionsdelaware[.]com
    • intopython[.]com
    • lalandscapelighting[.]com
    • lumenagnet[.]com
    • marbellaresales[.]com
    • miamipcsupport[.]com
    • moldinspectiondayton[.]com
    • nailscanai[.]com
    • newjerseypetsitter[.]com
    • numericagent[.]com
    • oaklandwaterdamage[.]com
    • oklahomawarehousing[.]com
    • olympiapetemergency[.]com
    • peaecagent[.]com
    • plasmaticsystems[.]com
    • plethorawallet[.]com
    • premierrentalpurchase[.]com
    • ricewaterbeauty[.]com
    • rvieragent[.]com
    • sandiegotkd[.]com
    • secueragent[.]com
    • shiledagent[.]com
    • syracusefertilitycenter[.]com
    • vastbets[.]com
    • wvaeagent[.]com

    Microsoft advised organizations to perform the following steps –

    • Educate users not to paste or run Terminal commands from untrusted websites, chat messages, apps, files, or phone-based instructions.
    • Monitor unusual Terminal, zsh, and shell sessions that retrieve payloads, decode content, or execute commands shortly after user interaction.
    • Correlate AppleScript-assisted shell activity with credential-store access, archive creation under temporary paths, and subsequent outbound traffic.
    • Monitor curl-based HTTP PUT uploads using --data-binary, API-key headers, upload identifiers, chunk indexes, total chunk counts, and recurring /gate URI patterns.
    • Investigate connections to suspicious or newly registered domains while continuing to hunt for the request and process patterns that may persist after infrastructure changes.

    Apple has separately documented three protections available on macOS 26.4 and later: Terminal paste protection, pasteboard command blocking, and AppleScript scanning.

    Cybersecurity

    After a 24-hour grace period following initial system setup, the Terminal warning applies when the user has not opened Terminal in more than 30 days, no common developer tooling is detected, and the paste originates from a specified application such as a web browser or messaging app.

    XProtect can trace the process tree produced by pasted terminal commands, check associated network artifacts against Apple’s Safe Browsing Service, and block behavior that matches known malware techniques. AppleScript and JavaScript for Automation executions are also inspected locally, including scripts executed directly from memory.

    The disclosure comes less than two weeks after Microsoft said it had confirmed more than 250 front-end domains in a macOS ClickFix campaign distributing MacSync and Atomic Stealer (AMOS) behind a server-side browser-fingerprinting gate. The August 18 report does not state that those front-end domains are the same infrastructure set as the more than 30 domains identified through the MacSync behavioral pivots.

    Domains infrastructure links MacSync Microsoft Rotating Stealer
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data

    16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets

    One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025

    Microsoft working on Defender patch for ShieldBreak zero-day

    Heights Finance Data Breach Impacts at Least 1.2 Million Individuals

    Philips and GE investigating Clop ransomware data theft claims

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Lloyd’s Register assists with LNG carrier-to-FSU conversion for African gas project

    August 19, 2026

    ProPublica Is Reporting on the Pentagon’s $1 Trillion Budget — ProPublica

    August 19, 2026

    Contemplating death helps us to really value life | Death and dying

    August 19, 2026

    Is the government on course to end rough sleeping? – Full Fact

    August 19, 2026
    Latest Posts

    Tether’s XAUT Gains Shariah Certification for Islamic Finance

    July 27, 2026

    Nvidia and Tech Giants Launch AI Security Alliance

    July 27, 2026

    Perplexity Releases pplx, a Single-Binary CLI That Puts Its Search API in the Terminal for Coding Agents

    July 27, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Lloyd’s Register assists with LNG carrier-to-FSU conversion for African gas project

    August 19, 2026

    ProPublica Is Reporting on the Pentagon’s $1 Trillion Budget — ProPublica

    August 19, 2026

    Contemplating death helps us to really value life | Death and dying

    August 19, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.