Hunting MacSync Stealer via behavioral pivots
🔍 Microsoft Defender Experts expanded earlier reporting on MacSync Stealer, a macOS information stealer that rotates infrastructure rapidly. The investigation correlated recurring command-line, request, and upload traits to link over 30 domains and show active staged collection and chunked HTTP PUT exfiltration. The write-up maps payload retrieval, C2 check-in, collection, staging, and cleanup to durable hunting pivots.
