Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure

A sprawling cybercrime operation has been uncovered, with Microsoft linking over 30 rotating domains to a notorious malware infrastructure known as MacSync Stealer. This sophisticated threat affects users across multiple platforms, exploiting vulnerabilities in identity exposure and privilege escalation to unleash devastating attacks on unsuspecting victims.

At the heart of this operation lies a cleverly designed malware that seizes control of compromised devices, allowing attackers to siphon off sensitive data, including login credentials, credit card numbers, and personal identifiable information. What’s more concerning is the way these domains are rotated in real-time, making it incredibly difficult for security teams to pinpoint their targets.

MacSync Stealer, as its name suggests, was initially designed to target macOS devices. However, researchers have discovered that this malware can also affect Windows users, thanks to a clever use of cross-domain privilege escalation techniques. In essence, attackers are able to create temporary backdoors on compromised machines, which they then use to pivot into other networks and domains.

The scope of this operation is staggering, with Microsoft confirming that over 30 rotating domains have been linked to the MacSync Stealer infrastructure. These domains are constantly changing IP addresses, making it a challenge for security teams to track their activities. Moreover, researchers warn that this malware can also be used in conjunction with other threats, such as ransomware and phishing attacks.

This operation highlights a disturbing trend: attackers are increasingly exploiting vulnerabilities in identity exposure to unlock active attack paths. What does this mean for users? Essentially, it means that hackers are using stolen or compromised identities to gain unauthorized access to sensitive systems and data. The result is catastrophic, with victims often left unaware of the extent of the breach.

So what can you do to protect yourself from these kinds of attacks? First and foremost, prioritize strong passwords and multi-factor authentication for all online accounts. Second, keep your operating system and software up-to-date, as many vulnerabilities are patched with each new update. Finally, remain vigilant: be cautious when clicking on links or opening attachments, especially those from unknown sources.

In the face of these evolving threats, it’s clear that identity exposure remains a pressing concern for security professionals and users alike. By staying informed about emerging threats like MacSync Stealer, we can all take steps to safeguard our digital lives and prevent devastating attacks.


Source: The Hacker News — 2026-08-19