Microsoft smothers malware by tracking behavior instead of blocking domains



  • Microsoft says blocking domains is ineffective against MacSync Stealer’s evolving infrastructure
  • Defender experts tracked over 30 domains by analyzing behavioral patterns instead
  • Mitigation focuses on spotting suspicious shell sessions, osascript activity, and /tmp/sync archives

Microsoft says it has found a way to stop the dangerous MacSync Stealer malware by monitoring certain behaviors, rather than keeping track of the domains used in the attacks.

MacSync Stealer is a piece of infostealer malware built for the Apple ecosystem – it steals passwords, browser data, cookies, Keychain secrets, cryptocurrency wallets, Telegram sessions, SSH/cloud credentials and other sensitive information.

https://cdn.mos.cms.futurecdn.net/G8QNviZt3KrDbfWVANJrNM-1920-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

Leave a reply

Please enter your comment!
Please enter your name here

spot_imgspot_img