Malware.View on attack.mitre.org
Cuckoo Stealer is a macOS malware with characteristics of spyware and an infostealer that has been in use since at least 2024. Cuckoo Stealer is a universal Mach-O binary that can run on Intel or ARM-based Macs and has been spread through trojanized versions of various potentially unwanted programs or PUP's such as converters, cleaners, and uninstallers.
| Technique | Procedure example |
|---|---|
| T1027.008 Stripped Payloads |
Cuckoo Stealer is a stripped binary payload. |
| T1027.013 Encrypted/Encoded File |
Cuckoo Stealer strings are XOR-encrypted. |
| T1033 System Owner/User Discovery |
Cuckoo Stealer can discover and send the username from a compromised host to C2. |
| T1036.005 Match Legitimate Resource Name or Location |
Cuckoo Stealer has copied and renamed itself to DumpMediaSpotifyMusicConverter. |
| T1041 Exfiltration Over C2 Channel |
Cuckoo Stealer can send information about the targeted system to C2 including captured passwords, OS build, hostname, and username. |
| T1056.002 GUI Input Capture |
Cuckoo Stealer has captured passwords by prompting victims with a “macOS needs to access System Settings” GUI window. |
| T1057 Process Discovery |
Cuckoo Stealer can use `ps aux` to enumerate running processes. |
| T1059.002 AppleScript |
Cuckoo Stealer can use osascript to generate a password-stealing prompt, duplicate files and folders, and set environmental variables. |
| T1059.004 Unix Shell |
Cuckoo Stealer can spawn a bash shell to enable execution on compromised hosts. |
| T1071.001 Web Protocols |
Cuckoo Stealer can use the curl API for C2 communications. |
| T1074.001 Local Data Staging |
Cuckoo Stealer has staged collected application data from Safari, Notes, and Keychain to `/var/folder`. |
| T1082 System Information Discovery |
Cuckoo Stealer can gather information about the OS version and hardware on compromised hosts. |
| T1083 File and Directory Discovery |
Cuckoo Stealer can search for files associated with specific applications. |
| T1095 Non-Application Layer Protocol |
Cuckoo Stealer can use sockets for communications to its C2 server. |
| T1113 Screen Capture |
Cuckoo Stealer can run `screencapture` to collect screenshots from compromised hosts. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.