Microsoft Has Found a New Way to Track Hacker Attacks on Users

a person working on a laptop / Curated Lifestyle
Фото: a person working on a laptop / Curated Lifestyle

Microsoft has announced a new approach to detecting the MacSync Stealer malware, which attacks macOS users. Instead of constantly blocking attacker domains, the company's experts began tracking characteristic behavioral patterns of the malware and its associated infrastructure.

This approach allowed Microsoft to link over 30 domains to the campaign. The company explains that blocking individual addresses was not sufficiently effective: after closing one domain, MacSync operators quickly moved their infrastructure to another.

MacSync Stealer belongs to the class of info-stealers - programs whose main task is to steal data. The malware can collect passwords, browser information, cookies, secrets from Keychain, cryptocurrency wallet data, Telegram sessions, as well as SSH keys and cloud service credentials.

MacSync was distributed using the ClickFix scheme. Users were lured to a malicious site where they were informed of a supposed problem - for example, an outdated browser or the need to pass a verification to access a document. The victim was then prompted to open Terminal on Mac and paste a command that actually triggered the infection.

Microsoft focused not on specific domains, but on sequences of actions that repeat during attacks. Among these signs are the characteristic launch of commands through the shell, the use of curl to download data, rapid transitions from osascript to network activity, and the creation of archives in the temporary directory before sending them to an external server.

Correlation of these signals allowed tracing not only the malware's communication channels with command-and-control servers, but also the stages of collecting, preparing, and exfiltrating stolen information.

For corporate cybersecurity teams, this means that traditional blocklists of domains are insufficient to counter campaigns whose infrastructure changes rapidly. Microsoft recommends focusing on combinations of processes and network activity that remain similar even after attackers move to new servers.

Source: Microsoft, TechRadar

analytics