Microsoft smothers malware by tracking behavior instead of blocking domains

https://cdn.mos.cms.futurecdn.net/G8QNviZt3KrDbfWVANJrNM-1920-80.jpg
  • Microsoft says blocking domains is ineffective against MacSync Stealer’s evolving infrastructure
  • Defender experts tracked over 30 domains by analyzing behavioral patterns instead
  • Mitigation focuses on spotting suspicious shell sessions, osascript activity, and /tmp/sync archives

Microsoft says it has found a way to stop the dangerous MacSync Stealer malware by monitoring certain behaviors, rather than keeping track of the domains used in the attacks.

MacSync Stealer is a piece of infostealer malware built for the Apple ecosystem - it steals passwords, browser data, cookies, Keychain secrets, cryptocurrency wallets, Telegram sessions, SSH/cloud credentials and other sensitive information.

It was being distributed via ClickFix scams. Victims would visit a malicious website which would tell them they had a problem (an outdated browser or a “protected” document that can only be viewed after “verifying” identities), and which would immediately offer a solution. That solution is to bring up the Terminal and paste a command...

Copyright of this story solely belongs to techradar.com. To see the full text click HERE

Read more