ATT&CKSoftwareCookieMiner

CookieMiner

S0492

Malware.View on attack.mitre.org

About this malware

CookieMiner is mac-based malware that targets information associated with cryptocurrency exchanges as well as enabling cryptocurrency mining on the victim system itself. It was first discovered in the wild in 2019.

Techniques used14

Procedure examples14

TechniqueProcedure example
T1005
Data from Local System

CookieMiner has retrieved iPhone text messages from iTunes phone backup files.

T1027.010
Command Obfuscation

CookieMiner has used base64 encoding to obfuscate scripts on the system.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol

CookieMiner has used the curl --upload-file command to exfiltrate data over HTTP.

T1059.004
Unix Shell

CookieMiner has used a Unix shell script to run a series of commands targeting macOS.

T1059.006
Python

CookieMiner has used python scripts on the user’s system, as well as the Python variant of the Empire agent, EmPyre.

T1083
File and Directory Discovery

CookieMiner has looked for files in the user's home directory with "wallet" in their name using find.

T1105
Ingress Tool Transfer

CookieMiner can download additional scripts from a web server.

T1140
Deobfuscate/Decode Files or Information

CookieMiner has used Google Chrome's decryption and extraction operations.

T1496.001
Compute Hijacking

CookieMiner has loaded coinmining software onto systems to mine for Koto cryptocurrency.

T1518.001
Security Software Discovery

CookieMiner has checked for the presence of "Little Snitch", macOS network monitoring and application firewall software, stopping and exiting if it is found.

T1539
Steal Web Session Cookie

CookieMiner can steal Google Chrome and Apple Safari browser cookies from the victim’s machine.

T1543.001
Launch Agent

CookieMiner has installed multiple new Launch Agents in order to maintain persistence for cryptocurrency mining software.

T1555.003
Credentials from Web Browsers

CookieMiner can steal saved usernames and passwords in Chrome as well as credit card credentials.

T1686
Disable or Modify System Firewall

CookieMiner has checked for the presence of "Little Snitch", macOS network monitoring and application firewall software, stopping and exiting if it is found.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. Unit42 CookieMiner Jan 2019 Open source
    Chen, y., et al. (2019, January 31). Mac Malware Steals Cryptocurrency Exchanges’ Cookies. Retrieved July 22, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.