📅 Source : Microsoft Security Blog, publié le 18 août 2026. Cette publication émane de Microsoft Defender Experts et Microsoft Security Research, en complément d’un premier signalement de RST Cloud (mai 2026).
🎯 Contexte général
MacSync Stealer est un infostealer ciblant exclusivement macOS, conçu pour exfiltrer des données sensibles via une infrastructure C2 à rotation rapide. L’analyse de Microsoft a permis de connecter plus de 30 domaines liés à cette activité grâce à une approche comportementale, là où RST Cloud n’en avait initialement identifié qu’un nombre limité.
🔗 Vecteur d’accès initial
L’exécution initiale repose sur la technique ClickFix : l’utilisateur est manipulé socialement pour coller et exécuter une commande dans un terminal zsh interactif. La commande utilise curl pour récupérer le payload depuis un chemin /curl/[token] sur une infrastructure contrôlée par l’attaquant.
⚙️ Chaîne d’attaque observée (6 phases)
- Récupération du payload : curl avec options
-kfsSLsur chemin/curl/, décodage viabase64etgunzip - Exécution assistée par AppleScript :
osascriptlance des commandes shell (sh,cp,rm,curl,mkdir,killall) - Collecte de données : Keychain macOS, credentials navigateurs (Chrome, Brave, Edge, Opera, Vivaldi, Arc, Chromium), cookies, IndexedDB, LevelDB, clés SSH, credentials AWS, configurations Kubernetes, Apple Notes, données Safari, fichiers sensibles (PDF, DOCX, TXT, KEY, PEM, KDBX, OVPN, WALLET, SEED), wallets crypto (Ledger, Trezor)
- Staging et compression : données archivées sous
/tmp/sync*, compressées en/tmp/osalogging.zip, découpées en chunks - Exfiltration : upload via
curlHTTP PUT avec--data-binary, headersapi-key, User-Agent macOS, paramètresupload_id,chunk_index,total_chunkssur chemin/gate?buildtxd= - Nettoyage : suppression des archives temporaires, dossiers de staging et fichiers de verrouillage
🔍 Pivots comportementaux durables identifiés
| Type | Valeur |
|---|---|
| Chemin URL | /curl/, /dynamic?txd=, /gate?buildtxd= |
| Paramètres URL | upload_id=, chunk_index=, total_chunks= |
| Options curl | -k -s --max-time, -X PUT --data-binary |
| Header | -H "api-key:" |
| User-Agent | Mozilla/5.0 (Macintosh...) |
| Chemins staging | /tmp/sync*, /tmp/osalogging.zip |
🛡️ Détections Microsoft Defender
Des signatures spécifiques ont été déployées : Trojan:MacOS/SuspMalScript, Behavior:MacOS/SuspOsascriptExec, Behavior:MacOS/SuspDownloadFileExec, Behavior:MacOS/SuspPassSteal, Trojan:MacOS/SuspDecodeExec, Behavior:MacOS/SuspInfoExfil, Trojan:MacOS/SuspMacSyncExfil.
🍎 Protections macOS 26.4
Apple a introduit dans macOS 26.4 des protections contre les attaques ClickFix : avertissement bloquant les collages potentiellement malveillants dans Terminal et vérifications XProtect.
📄 Type d’article : Publication de recherche technique à visée CTI, documentant la méthodologie de chasse comportementale et fournissant des IOCs domaines, des pivots comportementaux et des requêtes de chasse avancées pour Microsoft Defender XDR.
🧠 TTPs et IOCs détectés
TTP
- T1059.004 — Command and Scripting Interpreter: Unix Shell (Execution)
- T1105 — Ingress Tool Transfer (Command and Control)
- T1082 — System Information Discovery (Discovery)
- T1057 — Process Discovery (Discovery)
- T1518 — Software Discovery (Discovery)
- T1555.001 — Credentials from Password Stores: Keychain (Credential Access)
- T1555.003 — Credentials from Password Stores: Credentials from Web Browsers (Credential Access)
- T1005 — Data from Local System (Collection)
- T1552.001 — Unsecured Credentials: Credentials in Files (Credential Access)
- T1560.001 — Archive Collected Data: Archive via Utility (Collection)
- T1071.001 — Application Layer Protocol: Web Protocols (Command and Control)
- T1041 — Exfiltration Over C2 Channel (Exfiltration)
- T1020 — Automated Exfiltration (Exfiltration)
- T1030 — Data Transfer Size Limits (Exfiltration)
- T1070.004 — Indicator Removal: File Deletion (Defense Evasion)
- T1140 — Deobfuscate/Decode Files or Information (Defense Evasion)
IOC
- Domaines :
aihealthring.com— VT · URLhaus · ThreatFox - Domaines :
cabinrentalsnc.com— VT · URLhaus · ThreatFox - Domaines :
chatbasedos.com— VT · URLhaus · ThreatFox - Domaines :
commercialroofingsd.com— VT · URLhaus · ThreatFox - Domaines :
dogtrainersgeorgia.com— VT · URLhaus · ThreatFox - Domaines :
fintelliganceai.com— VT · URLhaus · ThreatFox - Domaines :
homeinspectionsdelaware.com— VT · URLhaus · ThreatFox - Domaines :
intopython.com— VT · URLhaus · ThreatFox - Domaines :
lalandscapelighting.com— VT · URLhaus · ThreatFox - Domaines :
lumenagnet.com— VT · URLhaus · ThreatFox - Domaines :
marbellaresales.com— VT · URLhaus · ThreatFox - Domaines :
miamipcsupport.com— VT · URLhaus · ThreatFox - Domaines :
moldinspectiondayton.com— VT · URLhaus · ThreatFox - Domaines :
nailscanai.com— VT · URLhaus · ThreatFox - Domaines :
newjerseypetsitter.com— VT · URLhaus · ThreatFox - Domaines :
numericagent.com— VT · URLhaus · ThreatFox - Domaines :
oaklandwaterdamage.com— VT · URLhaus · ThreatFox - Domaines :
oklahomawarehousing.com— VT · URLhaus · ThreatFox - Domaines :
olympiapetemergency.com— VT · URLhaus · ThreatFox - Domaines :
peaecagent.com— VT · URLhaus · ThreatFox - Domaines :
plasmaticsystems.com— VT · URLhaus · ThreatFox - Domaines :
plethorawallet.com— VT · URLhaus · ThreatFox - Domaines :
premierrentalpurchase.com— VT · URLhaus · ThreatFox - Domaines :
ricewaterbeauty.com— VT · URLhaus · ThreatFox - Domaines :
rvieragent.com— VT · URLhaus · ThreatFox - Domaines :
sandiegotkd.com— VT · URLhaus · ThreatFox - Domaines :
secueragent.com— VT · URLhaus · ThreatFox - Domaines :
shiledagent.com— VT · URLhaus · ThreatFox - Domaines :
syracusefertilitycenter.com— VT · URLhaus · ThreatFox - Domaines :
vastbets.com— VT · URLhaus · ThreatFox - Domaines :
wvaeagent.com— VT · URLhaus · ThreatFox - Fichiers :
osalogging.zip - Chemins :
/tmp/sync* - Chemins :
/tmp/osalogging.zip
⚠️ À propos de ces IOC — ils sont extraits automatiquement de l’article original le 20 août 2026 et n’ont pas fait l’objet d’une vérification externe. Un indicateur peut avoir été réattribué depuis : une IP de C2 peut redevenir un service légitime, un domaine sinkholé peut changer de propriétaire. Aucune garantie d’exactitude ni d’actualité — contrôlez leur validité avant tout usage opérationnel, en particulier avant de les injecter dans une blocklist ou un SIEM.
Malware / Outils
- MacSync Stealer (stealer)
🟢 Indice de vérification factuelle : 85/100 (haute)
- ✅ microsoft.com — source reconnue (liste interne) (20pts)
- ✅ 32482 chars — texte complet (fulltext extrait) (15pts)
- ✅ 34 IOCs (IPs/domaines/CVEs) (10pts)
- ✅ 3/3 IOCs confirmés (ThreatFox, URLhaus, VirusTotal) (15pts)
- ✅ 16 TTPs MITRE identifiées (15pts)
- ✅ date extraite du HTML source (10pts)
- ⬜ aucun acteur de menace nommé (0pts)
- ⬜ pas de CVE à vérifier (0pts)
IOCs confirmés externellement :
aihealthring.com(domain) → VT (17/91 détections)cabinrentalsnc.com(domain) → VT (14/91 détections)chatbasedos.com(domain) → VT (15/91 détections)
🔗 Source originale : https://www.microsoft.com/en-us/security/blog/2026/08/18/hunting-macsync-stealer-infrastructure-through-behavioral-pivots/