ATT&CKReferencesUnit42 CookieMiner Jan 2019

Unit42 CookieMiner Jan 2019

Chen, y., et al. (2019, January 31). Mac Malware Steals Cryptocurrency Exchanges’ Cookies. Retrieved July 22, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples14

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareCookieMiner

CookieMiner has retrieved iPhone text messages from iTunes phone backup files.

T1027.010
Command Obfuscation
MalwareCookieMiner

CookieMiner has used base64 encoding to obfuscate scripts on the system.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareCookieMiner

CookieMiner has used the curl --upload-file command to exfiltrate data over HTTP.

T1059.004
Unix Shell
MalwareCookieMiner

CookieMiner has used a Unix shell script to run a series of commands targeting macOS.

T1059.006
Python
MalwareCookieMiner

CookieMiner has used python scripts on the user’s system, as well as the Python variant of the Empire agent, EmPyre.

T1083
File and Directory Discovery
MalwareCookieMiner

CookieMiner has looked for files in the user's home directory with "wallet" in their name using find.

T1105
Ingress Tool Transfer
MalwareCookieMiner

CookieMiner can download additional scripts from a web server.

T1140
Deobfuscate/Decode Files or Information
MalwareCookieMiner

CookieMiner has used Google Chrome's decryption and extraction operations.

T1496.001
Compute Hijacking
MalwareCookieMiner

CookieMiner has loaded coinmining software onto systems to mine for Koto cryptocurrency.

T1518.001
Security Software Discovery
MalwareCookieMiner

CookieMiner has checked for the presence of "Little Snitch", macOS network monitoring and application firewall software, stopping and exiting if it is found.

T1539
Steal Web Session Cookie
MalwareCookieMiner

CookieMiner can steal Google Chrome and Apple Safari browser cookies from the victim’s machine.

T1543.001
Launch Agent
MalwareCookieMiner

CookieMiner has installed multiple new Launch Agents in order to maintain persistence for cryptocurrency mining software.

T1555.003
Credentials from Web Browsers
MalwareCookieMiner

CookieMiner can steal saved usernames and passwords in Chrome as well as credit card credentials.

T1686
Disable or Modify System Firewall
MalwareCookieMiner

CookieMiner has checked for the presence of "Little Snitch", macOS network monitoring and application firewall software, stopping and exiting if it is found.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.