💻
Microsoft defeats MacSync Stealer malware by tracking behaviour, not blocking domains
💻 Technology

Microsoft defeats MacSync Stealer malware by tracking behaviour, not blocking domains

Microsoft has developed a method to neutralise MacSync Stealer, an infostealer malware targeting Apple devices that steals passwords, browser data, cryptocurrency wallets, Telegram sessions and SSH credentials. Rather than blocking the attackers' constantly shifting domains, Microsoft Defender monitors suspicious shell sessions, osascript activity and /tmp/sync archives. Using behavioural analysis, Defender experts tracked over 30 domains linked to the malware, which was distributed via ClickFix scams.

Comments

No comments yet