Microsoft Exposes 30+ Rotating Domains Behind MacSync Data-Stealing Malware

Microsoft Exposes 30+ Rotating Domains Behind MacSync Data-Stealing Malware

Microsoft researchers have tied more than 30 constantly changing domains to MacSync Stealer, a malicious program that steals data from Mac computers. The moving infrastructure makes blocking the threat much harder.

Microsoft security researchers have identified a cluster of more than 30 rotating domains that are connected to the command-and-control infrastructure of a malicious program called MacSync Stealer. Rotating domains are website addresses that change frequently, often automatically, so that blocking one address does little to stop the attack. This discovery highlights how cybercriminals build flexible infrastructure that can stay online even as defenders try to shut it down.

MacSync Stealer is an information stealer, a type of malware designed to quietly collect sensitive data from an infected computer. While Microsoft's report does not list every capability of this specific program, stealers in general are known to harvest saved login credentials, browser cookies, autofill data, and sometimes cryptocurrency wallet files. The name suggests it targets Apple Mac computers, but the exact distribution method remains under investigation. For Mac users, this is a reminder that malware is not limited to Windows systems.

The use of more than 30 rotating domains is a deliberate evasion tactic. Attackers often register many domain names and cycle through them rapidly, sometimes using a domain generation algorithm that creates new addresses on a fixed schedule. This makes it difficult for security teams, internet service providers, and DNS filtering services to maintain an up-to-date blocklist. By the time one domain is blacklisted, the malware has already moved to the next one. For website owners and administrators, this underlines the importance of monitoring outbound traffic and keeping web applications patched, since compromised sites are frequently used to redirect visitors to such malicious domains.

Hosting providers and DNS services play a key role in this fight. A managed hosting environment can scan files for malicious code and block suspicious outbound connections, while a security-focused DNS resolver can stop requests to known bad domains before the browser ever connects to them. Because rotating domains change so quickly, real-time threat intelligence feeds are essential. AEU DNS, for example, offers private and secure DNS resolution that helps block access to known malicious domains at the network level, adding a protective layer for anyone browsing from a home or office network.

For individual Mac users and website owners, a few practical steps can reduce the risk of information stealers like MacSync Stealer. Keep the operating system and all applications up to date, since patches often close security holes that malware exploits. Be cautious about downloading software from unofficial websites or clicking links in unexpected emails, as these are common ways stealers get installed. Turn on two-factor authentication for important accounts so that even if a password is stolen, the account remains protected. Use a reputable security product that can detect and remove malware. Finally, consider changing your DNS settings to a security-focused provider that filters known malicious domains.

How to Protect Yourself

  1. Keep your Mac's operating system and all apps updated to the latest version, because updates fix security weaknesses that stealers use to get in.
  2. Only download programs from the official Mac App Store or the developer's own website, and avoid clicking links or attachments in unexpected emails.
  3. Turn on two-factor authentication (a second login step, like a code from your phone) for your email, hosting account, and any other important online accounts.
  4. Install and regularly run a reputable antivirus or anti-malware program for Mac, even though Macs are often considered safer.
  5. Change your computer's DNS settings to a secure DNS provider that blocks known malicious websites before they load.

Related AEU services

  • AEU-I IT and security consulting
  • AEU Data Cloud and data infrastructure