ATT&CKSoftwaremacOS.OSAMiner

macOS.OSAMiner

S1048

Malware.View on attack.mitre.org

About this malware

macOS.OSAMiner is a Monero mining trojan that was first observed in 2018; security researchers assessed macOS.OSAMiner may have been circulating since at least 2015. macOS.OSAMiner is known for embedding one run-only AppleScript into another, which helped the malware evade full analysis for five years due to a lack of Apple event (AEVT) analysis tools.

Techniques used11

Procedure examples11

TechniqueProcedure example
T1027.008
Stripped Payloads

macOS.OSAMiner has used run-only Applescripts, a compiled and stripped version of AppleScript, to remove human readable indicators to evade detection.

T1027.009
Embedded Payloads

macOS.OSAMiner has embedded Stripped Payloads within another run-only Stripped Payloads.

T1057
Process Discovery

macOS.OSAMiner has used `ps ax | grep <name> | grep -v grep | ...` and `ps ax | grep -E...` to conduct process discovery.

T1059.002
AppleScript

macOS.OSAMiner has used `osascript` to call itself via the `do shell script` command in the Launch Agent `.plist` file.

T1082
System Information Discovery

macOS.OSAMiner can gather the device serial number.

T1105
Ingress Tool Transfer

macOS.OSAMiner has used `curl` to download a Stripped Payloads from a public facing adversary-controlled webpage.

T1497.001
System Checks

macOS.OSAMiner can parse the output of the native `system_profiler` tool to determine if the machine is running with 4 cores.

T1543.001
Launch Agent

macOS.OSAMiner has placed a Stripped Payloads with a `plist` extension in the Launch Agent's folder.

T1569.001
Launchctl

macOS.OSAMiner has used `launchctl` to restart the Launch Agent.

T1680
Local Storage Discovery

macOS.OSAMiner has checked to ensure there is enough disk space using the Unix utility `df`.

T1685
Disable or Modify Tools

macOS.OSAMiner has searched for the Activity Monitor process in the System Events process list and kills the process if running. macOS.OSAMiner also searches the operating system's `install.log` for apps matching its hardcoded list, killing all matching process names.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References2

  1. SentinelLabs reversing run-only applescripts 2021 Open source
    Phil Stokes. (2021, January 11). FADE DEAD | Adventures in Reversing Malicious Run-Only AppleScripts. Retrieved September 29, 2022.
  2. VMRay OSAMiner dynamic analysis 2021 Open source
    VMRAY. (2021, January 14). Malware Analysis Spotlight: OSAMiner Uses Run-Only AppleScripts to Evade Detection. Retrieved October 4, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.